Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2010-10-28 00:00
Updated : 2010-10-28 04:00
NVD link : CVE-2010-3842
Mitre link : CVE-2010-3842
CVE.ORG link : CVE-2010-3842
JSON object : View
Products Affected
curl
- curl
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')