CVE-2010-3306

Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
salvo_g._tomaselliweborf
𝑥
≤ 0.12.2
salvo_g._tomaselliweborf
0.3
salvo_g._tomaselliweborf
0.4
salvo_g._tomaselliweborf
0.5
salvo_g._tomaselliweborf
0.6
salvo_g._tomaselliweborf
0.7
salvo_g._tomaselliweborf
0.8
salvo_g._tomaselliweborf
0.9
salvo_g._tomaselliweborf
0.10
salvo_g._tomaselliweborf
0.11
salvo_g._tomaselliweborf
0.12
salvo_g._tomaselliweborf
0.12.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
weborf
bullseye
0.17-3+deb11u1
fixed
bookworm
0.19-2.1+deb12u1
fixed
sid
1.4-1
fixed
trixie
1.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
weborf
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
ignored
karmic
dne
jaunty
dne
hardy
dne
dapper
dne