Record summary

CVE-2013-4885 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.

Description

The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBNmap - Arbitrary File WriteExploitDB exploitby Piotr DuszynskiNot analyzed1 file
ExploitDB

PoC details

References

7