CVE-2004-0273
 
Severity Score
9.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.
Vulnerabilidad de atravesamiento de directorios en RealOne Player, RealOne Player 2.0, y RealOne Enterprise Desktop permite a atacantes remotos subir ficheros arbitrarios mediante un fichero RMP que contenga secuencias .. (punto punto) en fichero de piel .rjs.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2004-03-17 CVE Reserved
- 2004-09-01 CVE Published
- 2024-08-08 CVE Updated
- 2024-09-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=bugtraq&m=107642978524321&w=2 | Mailing List | |
http://www.kb.cert.org/vuls/id/514734 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15123 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://service.real.com/help/faq/security/040123_player/EN | 2017-10-10 | |
http://www.securityfocus.com/bid/9580 | 2017-10-10 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Realnetworks Search vendor "Realnetworks" | Realone Desktop Manager Search vendor "Realnetworks" for product "Realone Desktop Manager" | * | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Realone Enterprise Desktop Search vendor "Realnetworks" for product "Realone Enterprise Desktop" | 6.0.11.774 Search vendor "Realnetworks" for product "Realone Enterprise Desktop" and version "6.0.11.774" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Realone Player Search vendor "Realnetworks" for product "Realone Player" | 1.0 Search vendor "Realnetworks" for product "Realone Player" and version "1.0" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Realone Player Search vendor "Realnetworks" for product "Realone Player" | 2.0 Search vendor "Realnetworks" for product "Realone Player" and version "2.0" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Realone Player Search vendor "Realnetworks" for product "Realone Player" | 2.0 Search vendor "Realnetworks" for product "Realone Player" and version "2.0" | win |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Realone Player Search vendor "Realnetworks" for product "Realone Player" | 6.0.11.818 Search vendor "Realnetworks" for product "Realone Player" and version "6.0.11.818" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Realone Player Search vendor "Realnetworks" for product "Realone Player" | 6.0.11.830 Search vendor "Realnetworks" for product "Realone Player" and version "6.0.11.830" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Realone Player Search vendor "Realnetworks" for product "Realone Player" | 6.0.11.841 Search vendor "Realnetworks" for product "Realone Player" and version "6.0.11.841" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Realone Player Search vendor "Realnetworks" for product "Realone Player" | 6.0.11.853 Search vendor "Realnetworks" for product "Realone Player" and version "6.0.11.853" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Realone Player Search vendor "Realnetworks" for product "Realone Player" | 6.0.11.868 Search vendor "Realnetworks" for product "Realone Player" and version "6.0.11.868" | - |
Affected
|