CVE-2010-0620

EMC HomeBase Server 6.2.x < 6.2.3 and 6.3.x < 6.3.2 - Path Traversal and Arbitrary File Write

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-0620. PoCs published by Metasploit.

AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability in EMC HomeBase Server 6.3.0 to achieve remote code execution by uploading a malicious executable and a MOF file to trigger its execution.

Description

Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/17219

This Metasploit module exploits a directory traversal vulnerability in EMC HomeBase Server 6.3.0 to achieve remote code execution by uploading a malicious executable and a MOF file to trigger its execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: EMC HomeBase Server 6.3.0
No auth needed
Prerequisites: Network access to the target system on port 18821 · EMC HomeBase Server 6.3.0 running on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8230
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38380
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/509723/100/0/threaded
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0458
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-10-020/

Scores

EPSS 0.1948
EPSS Percentile 97.0%

Details

CWE
CWE-22
Status published
Products (2)
emc/homebase_server 6.2
emc/homebase_server 6.3
Published Feb 25, 2010
Tracked Since Feb 18, 2026