CVE-2010-0933: Path Traversal
Published Mar 5, 2010
·Updated
Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a .. (dot dot) in the argument to the "p4 add" command.
Affected Software
1 affected component
Perforce Perforce Server=2008.1
Event History
Mar 5, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0933?
The severity of CVE-2010-0933 is considered medium due to the potential unauthorized file creation.
2
How do I fix CVE-2010-0933?
To fix CVE-2010-0933, upgrade to a version of Perforce Server that is not vulnerable, or apply any available patches from the vendor.
3
Who is affected by CVE-2010-0933?
CVE-2010-0933 affects remote authenticated users of Perforce Server version 2008.1.
4
What type of vulnerability is CVE-2010-0933?
CVE-2010-0933 is a directory traversal vulnerability that allows file creation through manipulated commands.
5
Can CVE-2010-0933 be exploited remotely?
Yes, CVE-2010-0933 can be exploited remotely by authenticated users manipulating the 'p4 add' command.