nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.
References
Link | Resource |
---|---|
https://nmap.org/changelog.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-04-18 12:29
Updated : 2018-05-24 05:08
NVD link : CVE-2018-1000161
Mitre link : CVE-2018-1000161
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
nmap
- nmap