CVE-2016-10733: Path Traversal
Published Oct 28, 2018
·Updated
ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
Affected Software
1 affected component
ProjectSend ProjectSend=582
Event History
Oct 28, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is CVE-2016-10733?
CVE-2016-10733 is a vulnerability in ProjectSend (formerly cFTP) r582 that allows directory traversal via a query string parameter.
2
How does CVE-2016-10733 impact ProjectSend?
CVE-2016-10733 allows an attacker to perform directory traversal attacks, potentially accessing files outside of the intended directory structure.
3
What is the severity of CVE-2016-10733?
The severity of CVE-2016-10733 is critical, with a CVSS score of 9.8.
4
How can I fix CVE-2016-10733 in ProjectSend?
To fix CVE-2016-10733, it is recommended to upgrade to a patched version of ProjectSend.
5
Is there any additional information about CVE-2016-10733?
Yes, you can find more details about CVE-2016-10733 in the reference link provided: https://github.com/sandboxescape/ProjectSend-multiple-vulnerabilities/