CVE-2010-2627
EA Battlefield 2 / Battlefield 2142 - Multiple Arbitrary File Upload Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.48.0) and earlier, allow remote servers to overwrite arbitrary files on the client via "..\" (dot dot backslash) sequences in URLs for the (1) sponsor or (2) community logos, and other URLs related to (3) DemoDownloadURL, (4) DemoIndexURL and (5) CustomMapsURL.
MĂșltiples vulnerabilidades de salto de directorio en el motor de Refractor 2, tal como se utiliza en Battlefield 2 v1.50 (v1.5.3153-802.0) y anteriores, y Battlefield 2142 (v1.10.48.0) y anteriores, permiten a servidores remotos sobrescribir archivos arbitrarios en el cliente a travĂ©s de secuencias "..\"(punto-punto-barra invertida) en las direcciones URL de (1) el patrocinador (2) logotipos de la comunidad y otras URL relacionadas con (3) DemoDownloadURL, (4) DemoIndexURL y (5) CustomMapsURL.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-07-02 CVE Reserved
- 2010-07-02 CVE Published
- 2010-07-08 First Exploit
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://aluigi.altervista.org/adv/bf2urlz-adv.txt | X_refsource_misc | |
http://www.securityfocus.com/bid/41262 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/14267 | 2010-07-08 | |
http://osvdb.org/65863 | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/40334 | 2010-07-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ea Search vendor "Ea" | Battlefield 2 Search vendor "Ea" for product "Battlefield 2" | <= 2.1.50 Search vendor "Ea" for product "Battlefield 2" and version " <= 2.1.50" | - |
Affected
| ||||||
Ea Search vendor "Ea" | Battlefield 2142 Search vendor "Ea" for product "Battlefield 2142" | <= 1.10.48.0 Search vendor "Ea" for product "Battlefield 2142" and version " <= 1.10.48.0" | - |
Affected
|