CVE-2013-4885

The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
nmapnmap
𝑥
≤ 6.25
nmapnmap
2.1:beta1
nmapnmap
2.2:beta2
nmapnmap
2.2:beta3
nmapnmap
2.2:beta4
nmapnmap
2.3:beta10
nmapnmap
2.3:beta12
nmapnmap
2.3:beta13
nmapnmap
2.3:beta14
nmapnmap
2.3:beta17
nmapnmap
2.3:beta18
nmapnmap
2.3:beta19
nmapnmap
2.3:beta20
nmapnmap
2.3:beta21
nmapnmap
2.3:beta4
nmapnmap
2.3:beta5
nmapnmap
2.3:beta6
nmapnmap
2.3:beta8
nmapnmap
2.3:beta9
nmapnmap
2.05
nmapnmap
2.06
nmapnmap
2.07
nmapnmap
2.08
nmapnmap
2.09
nmapnmap
2.10
nmapnmap
2.11
nmapnmap
2.12
nmapnmap
2.50
nmapnmap
2.51
nmapnmap
2.52
nmapnmap
2.53
nmapnmap
2.54:beta1
nmapnmap
2.54:beta16
nmapnmap
2.54:beta19
nmapnmap
2.54:beta2
nmapnmap
2.54:beta20
nmapnmap
2.54:beta21
nmapnmap
2.54:beta22
nmapnmap
2.54:beta24
nmapnmap
2.54:beta25
nmapnmap
2.54:beta26
nmapnmap
2.54:beta27
nmapnmap
2.54:beta28
nmapnmap
2.54:beta29
nmapnmap
2.54:beta3
nmapnmap
2.54:beta30
nmapnmap
2.54:beta31
nmapnmap
2.54:beta32
nmapnmap
2.54:beta33
nmapnmap
2.54:beta34
nmapnmap
2.54:beta35
nmapnmap
2.54:beta36
nmapnmap
2.54:beta37
nmapnmap
2.54:beta4
nmapnmap
2.54:beta5
nmapnmap
2.54:beta6
nmapnmap
2.54:beta7
nmapnmap
2.99:rc1
nmapnmap
2.99:rc2
nmapnmap
3.00
nmapnmap
3.10:alpha1
nmapnmap
3.10:alpha2
nmapnmap
3.10:alpha3
nmapnmap
3.10:alpha4
nmapnmap
3.10:alpha5
nmapnmap
3.10:alpha7
nmapnmap
3.10:alpha9
nmapnmap
3.15:beta1
nmapnmap
3.15:beta2
nmapnmap
3.15:beta3
nmapnmap
3.20
nmapnmap
3.25
nmapnmap
3.26
nmapnmap
3.27
nmapnmap
3.28
nmapnmap
3.30
nmapnmap
3.40:pvt1
nmapnmap
3.40:pvt10
nmapnmap
3.40:pvt11
nmapnmap
3.40:pvt12
nmapnmap
3.40:pvt13
nmapnmap
3.40:pvt14
nmapnmap
3.40:pvt15
nmapnmap
3.40:pvt16
nmapnmap
3.40:pvt17
nmapnmap
3.40:pvt2
nmapnmap
3.40:pvt3
nmapnmap
3.40:pvt4
nmapnmap
3.40:pvt6
nmapnmap
3.40:pvt7
nmapnmap
3.40:pvt8
nmapnmap
3.40:pvt9
nmapnmap
3.45
nmapnmap
3.48
nmapnmap
3.50
nmapnmap
3.55
nmapnmap
3.70
nmapnmap
3.75
nmapnmap
3.81
nmapnmap
3.90
nmapnmap
3.91
nmapnmap
3.93
nmapnmap
3.94:alpha1
nmapnmap
3.94:alpha2
nmapnmap
3.94:alpha3
nmapnmap
3.95
nmapnmap
3.96:beta1
nmapnmap
3.98:beta1
nmapnmap
3.99
nmapnmap
3.999
nmapnmap
3.9999
nmapnmap
4.00
nmapnmap
4.01
nmapnmap
4.02:alpha1
nmapnmap
4.02:alpha2
nmapnmap
4.03
nmapnmap
4.04:beta1
nmapnmap
4.10
nmapnmap
4.11
nmapnmap
4.20
nmapnmap
4.20:alpha1
nmapnmap
4.20:alpha10
nmapnmap
4.20:alpha11
nmapnmap
4.20:alpha2
nmapnmap
4.20:alpha3
nmapnmap
4.20:alpha4
nmapnmap
4.20:alpha5
nmapnmap
4.20:alpha6
nmapnmap
4.20:alpha7
nmapnmap
4.20:alpha8
nmapnmap
4.20:alpha9
nmapnmap
4.20:rc1
nmapnmap
4.20:rc2
nmapnmap
4.21:alpha1
nmapnmap
4.21:alpha2
nmapnmap
4.21:alpha3
nmapnmap
4.21:alpha4
nmapnmap
4.22:soc1
nmapnmap
4.22:soc2
nmapnmap
4.22:soc3
nmapnmap
4.22:soc5
nmapnmap
4.22:soc6
nmapnmap
4.22:soc7
nmapnmap
4.22:soc8
nmapnmap
4.49:rc1
nmapnmap
4.49:rc2
nmapnmap
4.49:rc3
nmapnmap
4.49:rc4
nmapnmap
4.49:rc5
nmapnmap
4.49:rc6
nmapnmap
4.49:rc7
nmapnmap
4.50
nmapnmap
4.51:beta
nmapnmap
4.52
nmapnmap
4.53
nmapnmap
4.60
nmapnmap
4.62
nmapnmap
4.65
nmapnmap
4.68
nmapnmap
4.75
nmapnmap
4.76
nmapnmap
4.85:beta1
nmapnmap
4.85:beta10
nmapnmap
4.85:beta2
nmapnmap
4.85:beta3
nmapnmap
4.85:beta4
nmapnmap
4.85:beta5
nmapnmap
4.85:beta6
nmapnmap
4.85:beta7
nmapnmap
4.85:beta8
nmapnmap
4.85:beta9
nmapnmap
4.90:rc1
nmapnmap
5.00
nmapnmap
5.10:beta1
nmapnmap
5.10:beta2
nmapnmap
5.20
nmapnmap
5.21
nmapnmap
5.30:beta1
nmapnmap
5.35:dc1
nmapnmap
5.50
nmapnmap
5.51
nmapnmap
5.59:beta1
nmapnmap
5.61:test1
nmapnmap
5.61:test2
nmapnmap
5.61:test4
nmapnmap
5.61:test5
nmapnmap
6.00
nmapnmap
6.01
nmapnmap
6.20:beta1
opensuseopensuse
12.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nmap
bullseye
7.91+dfsg1+really7.80+dfsg1-2
fixed
squeeze
not-affected
bookworm
7.93+dfsg1-1
fixed
sid
7.94+git20230807.3be01efb1+dfsg-4
fixed
trixie
7.94+git20230807.3be01efb1+dfsg-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nmap
trusty
Fixed 6.40-0.1
released
saucy
Fixed 6.40-0.1
released
raring
ignored
quantal
ignored
precise
not-affected
lucid
ignored