CVE-2004-0273

critical

Description

Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/15123

http://www.securityfocus.com/bid/9580

http://www.kb.cert.org/vuls/id/514734

http://service.real.com/help/faq/security/040123_player/EN/

http://marc.info/?l=bugtraq&m=107642978524321&w=2

Details

Source: Mitre, NVD

Published: 2004-11-23

Updated: 2017-10-10

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical