CVE-2018-1000161
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.
nmap, de la versión 6.49BETA6 hasta la 7.60, hasta e incluyendo la revisión SVN 37147, contiene una vulnerabilidad de salto de directorio de salto de directorio en el script NSE http-fetch que puede resultar en la sobrescritura de archivos según el usuario lo ejecuta. Este ataque parece ser explotable mediante una víctima que ejecuta el script NSE http-fetch contra un sitio web malicioso. La vulnerabilidad parece haber sido solucionada en la versión 7.7.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-27 CVE Reserved
- 2018-04-18 CVE Published
- 2024-02-26 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nmap Search vendor "Nmap" | Nmap Search vendor "Nmap" for product "Nmap" | 6.49 Search vendor "Nmap" for product "Nmap" and version "6.49" | beta6 |
Affected
| ||||||
Nmap Search vendor "Nmap" | Nmap Search vendor "Nmap" for product "Nmap" | 7.00 Search vendor "Nmap" for product "Nmap" and version "7.00" | - |
Affected
| ||||||
Nmap Search vendor "Nmap" | Nmap Search vendor "Nmap" for product "Nmap" | 7.01 Search vendor "Nmap" for product "Nmap" and version "7.01" | - |
Affected
| ||||||
Nmap Search vendor "Nmap" | Nmap Search vendor "Nmap" for product "Nmap" | 7.10 Search vendor "Nmap" for product "Nmap" and version "7.10" | - |
Affected
| ||||||
Nmap Search vendor "Nmap" | Nmap Search vendor "Nmap" for product "Nmap" | 7.11 Search vendor "Nmap" for product "Nmap" and version "7.11" | - |
Affected
| ||||||
Nmap Search vendor "Nmap" | Nmap Search vendor "Nmap" for product "Nmap" | 7.12 Search vendor "Nmap" for product "Nmap" and version "7.12" | - |
Affected
| ||||||
Nmap Search vendor "Nmap" | Nmap Search vendor "Nmap" for product "Nmap" | 7.25 Search vendor "Nmap" for product "Nmap" and version "7.25" | beta1 |
Affected
| ||||||
Nmap Search vendor "Nmap" | Nmap Search vendor "Nmap" for product "Nmap" | 7.25 Search vendor "Nmap" for product "Nmap" and version "7.25" | beta2 |
Affected
| ||||||
Nmap Search vendor "Nmap" | Nmap Search vendor "Nmap" for product "Nmap" | 7.30 Search vendor "Nmap" for product "Nmap" and version "7.30" | - |
Affected
| ||||||
Nmap Search vendor "Nmap" | Nmap Search vendor "Nmap" for product "Nmap" | 7.31 Search vendor "Nmap" for product "Nmap" and version "7.31" | - |
Affected
| ||||||
Nmap Search vendor "Nmap" | Nmap Search vendor "Nmap" for product "Nmap" | 7.40 Search vendor "Nmap" for product "Nmap" and version "7.40" | - |
Affected
| ||||||
Nmap Search vendor "Nmap" | Nmap Search vendor "Nmap" for product "Nmap" | 7.50 Search vendor "Nmap" for product "Nmap" and version "7.50" | - |
Affected
| ||||||
Nmap Search vendor "Nmap" | Nmap Search vendor "Nmap" for product "Nmap" | 7.60 Search vendor "Nmap" for product "Nmap" and version "7.60" | - |
Affected
|