First published: Fri Jul 02 2010(Updated: )
Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.48.0) and earlier, allow remote servers to overwrite arbitrary files on the client via "..\" (dot dot backslash) sequences in URLs for the (1) sponsor or (2) community logos, and other URLs related to (3) DemoDownloadURL, (4) DemoIndexURL and (5) CustomMapsURL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Battlefield 2142 | <=1.10.48.0 | |
Battlefield 2 | <=2.1.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2627 is classified as a medium-severity vulnerability due to the potential for remote file overwriting.
To mitigate CVE-2010-2627, users should update to the latest version of Battlefield 2 and Battlefield 2142 that addresses this vulnerability.
CVE-2010-2627 affects Battlefield 2 version up to 1.50 and Battlefield 2142 version up to 1.10.48.0.
CVE-2010-2627 is a directory traversal vulnerability allowing attackers to access and overwrite arbitrary files on the client.
Yes, CVE-2010-2627 can be exploited remotely by sending specially crafted URLs that utilize directory traversal sequences.