Description
Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Auriemma Luigi · textremotemultiple
https://www.exploit-db.com/exploits/22224
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/6775
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/11299
Scores
EPSS
0.0359
EPSS Percentile
87.8%
Details
CWE
CWE-22
Status
published
Products (3)
epic_games/unreal_engine
226f
epic_games/unreal_engine
433
epic_games/unreal_engine
436
Published
Dec 31, 2003
Tracked Since
Feb 18, 2026