CVE-2009-2968
VMware Studio 2.0 public beta - Path Traversal and Arbitrary File Write via Web Interface
Title source: llmDescription
Directory traversal vulnerability in a support component in the web interface in VMware Studio 2.0 public beta before build 1017-185256 allows remote attackers to upload files to arbitrary locations via unspecified vectors.
References (7)
Core 7
Core References
Vendor Advisory x_refsource_confirm
http://www.vmware.com/support/developer/studio/studio20/release_notes.html
Vendor Advisory mailing-list
x_refsource_mlist
http://lists.vmware.com/pipermail/security-announce/2009/000064.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/506191/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/52976
Vendor Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2009-0011.html
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2501
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/36199
Scores
EPSS
0.0031
EPSS Percentile
54.4%
Details
CWE
CWE-22
Status
published
Products (1)
vmware/studio
2.0 beta
Published
Sep 02, 2009
Tracked Since
Feb 18, 2026