CVE-2016-1505
CRITICALRadicale < 1.1 - Path Traversal and Arbitrary File Write via Filesystem Storage Backend
Title source: llmDescription
The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted path, as demonstrated by /c:/file/ignore.
References (7)
Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/80255
Patch x_refsource_confirm
https://github.com/Kozea/Radicale/pull/343
Patch x_refsource_confirm
https://github.com/Unrud/Radicale/commit/b4b3d51f33c7623d312f289252dd7bbb8f58bbe6
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/01/06/7
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/01/05/7
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/01/06/4
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/01/07/7
Scores
CVSS v3
10.0
EPSS
0.0259
EPSS Percentile
83.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Details
CWE
CWE-21
Status
published
Products (2)
pypi/Radicale
0 - 1.1PyPI
radicale/radicale
< 1.0.1
Published
Feb 03, 2016
Tracked Since
Feb 18, 2026