7.5

CVE-2010-2251

The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.

Data is provided by the National Vulnerability Database (NVD)
Alexander V. LukyanovLftp Version <= 4.0.5
Alexander V. LukyanovLftp Version2.0.0
Alexander V. LukyanovLftp Version2.0.1
Alexander V. LukyanovLftp Version2.0.2
Alexander V. LukyanovLftp Version2.0.3
Alexander V. LukyanovLftp Version2.0.4
Alexander V. LukyanovLftp Version2.0.5
Alexander V. LukyanovLftp Version2.1.0
Alexander V. LukyanovLftp Version2.1.1
Alexander V. LukyanovLftp Version2.1.2
Alexander V. LukyanovLftp Version2.1.3
Alexander V. LukyanovLftp Version2.1.4
Alexander V. LukyanovLftp Version2.1.5
Alexander V. LukyanovLftp Version2.1.6
Alexander V. LukyanovLftp Version2.1.7
Alexander V. LukyanovLftp Version2.1.8
Alexander V. LukyanovLftp Version2.1.9
Alexander V. LukyanovLftp Version2.1.10
Alexander V. LukyanovLftp Version2.2.0
Alexander V. LukyanovLftp Version2.2.0a
Alexander V. LukyanovLftp Version2.2.1
Alexander V. LukyanovLftp Version2.2.2
Alexander V. LukyanovLftp Version2.2.3
Alexander V. LukyanovLftp Version2.2.4
Alexander V. LukyanovLftp Version2.2.5
Alexander V. LukyanovLftp Version2.2.6
Alexander V. LukyanovLftp Version2.3
Alexander V. LukyanovLftp Version2.3.0
Alexander V. LukyanovLftp Version2.3.1
Alexander V. LukyanovLftp Version2.3.2
Alexander V. LukyanovLftp Version2.3.3
Alexander V. LukyanovLftp Version2.3.4
Alexander V. LukyanovLftp Version2.3.5
Alexander V. LukyanovLftp Version2.3.6
Alexander V. LukyanovLftp Version2.3.7
Alexander V. LukyanovLftp Version2.3.8
Alexander V. LukyanovLftp Version2.3.9
Alexander V. LukyanovLftp Version2.3.10
Alexander V. LukyanovLftp Version2.3.11
Alexander V. LukyanovLftp Version2.4.0
Alexander V. LukyanovLftp Version2.4.1
Alexander V. LukyanovLftp Version2.4.2
Alexander V. LukyanovLftp Version2.4.3
Alexander V. LukyanovLftp Version2.4.5
Alexander V. LukyanovLftp Version2.4.6
Alexander V. LukyanovLftp Version2.4.7
Alexander V. LukyanovLftp Version2.4.8
Alexander V. LukyanovLftp Version2.4.9
Alexander V. LukyanovLftp Version2.4.10
Alexander V. LukyanovLftp Version2.4.10a
Alexander V. LukyanovLftp Version2.5.0
Alexander V. LukyanovLftp Version2.5.1
Alexander V. LukyanovLftp Version2.5.2
Alexander V. LukyanovLftp Version2.5.3
Alexander V. LukyanovLftp Version2.5.4
Alexander V. LukyanovLftp Version2.6.0
Alexander V. LukyanovLftp Version2.6.1
Alexander V. LukyanovLftp Version2.6.2
Alexander V. LukyanovLftp Version2.6.3
Alexander V. LukyanovLftp Version2.6.4
Alexander V. LukyanovLftp Version2.6.5
Alexander V. LukyanovLftp Version2.6.6
Alexander V. LukyanovLftp Version2.6.7
Alexander V. LukyanovLftp Version2.6.8
Alexander V. LukyanovLftp Version2.6.9
Alexander V. LukyanovLftp Version2.6.10
Alexander V. LukyanovLftp Version2.6.11
Alexander V. LukyanovLftp Version2.6.12
Alexander V. LukyanovLftp Version3.0.0
Alexander V. LukyanovLftp Version3.0.1
Alexander V. LukyanovLftp Version3.0.2
Alexander V. LukyanovLftp Version3.0.3
Alexander V. LukyanovLftp Version3.0.4
Alexander V. LukyanovLftp Version3.0.5
Alexander V. LukyanovLftp Version3.0.6
Alexander V. LukyanovLftp Version3.0.7
Alexander V. LukyanovLftp Version3.0.8
Alexander V. LukyanovLftp Version3.0.9
Alexander V. LukyanovLftp Version3.0.10
Alexander V. LukyanovLftp Version3.0.11
Alexander V. LukyanovLftp Version3.0.12
Alexander V. LukyanovLftp Version3.0.13
Alexander V. LukyanovLftp Version3.1.0
Alexander V. LukyanovLftp Version3.1.1
Alexander V. LukyanovLftp Version3.1.2
Alexander V. LukyanovLftp Version3.1.3
Alexander V. LukyanovLftp Version3.2.0
Alexander V. LukyanovLftp Version3.2.1
Alexander V. LukyanovLftp Version3.3.0
Alexander V. LukyanovLftp Version3.3.1
Alexander V. LukyanovLftp Version3.3.2
Alexander V. LukyanovLftp Version3.3.3
Alexander V. LukyanovLftp Version3.3.4
Alexander V. LukyanovLftp Version3.3.5
Alexander V. LukyanovLftp Version3.4.0
Alexander V. LukyanovLftp Version3.4.1
Alexander V. LukyanovLftp Version3.4.2
Alexander V. LukyanovLftp Version3.4.3
Alexander V. LukyanovLftp Version3.4.4
Alexander V. LukyanovLftp Version3.4.5
Alexander V. LukyanovLftp Version3.4.6
Alexander V. LukyanovLftp Version3.4.7
Alexander V. LukyanovLftp Version3.5.0
Alexander V. LukyanovLftp Version3.5.1
Alexander V. LukyanovLftp Version3.5.2
Alexander V. LukyanovLftp Version3.5.3
Alexander V. LukyanovLftp Version3.5.4
Alexander V. LukyanovLftp Version3.5.5
Alexander V. LukyanovLftp Version3.5.6
Alexander V. LukyanovLftp Version3.5.7
Alexander V. LukyanovLftp Version3.5.8
Alexander V. LukyanovLftp Version3.5.9
Alexander V. LukyanovLftp Version3.5.10
Alexander V. LukyanovLftp Version3.5.11
Alexander V. LukyanovLftp Version3.5.12
Alexander V. LukyanovLftp Version3.5.13
Alexander V. LukyanovLftp Version3.5.14
Alexander V. LukyanovLftp Version3.5.15
Alexander V. LukyanovLftp Version3.6.0
Alexander V. LukyanovLftp Version3.6.1
Alexander V. LukyanovLftp Version3.6.2
Alexander V. LukyanovLftp Version3.6.3
Alexander V. LukyanovLftp Version3.7.0
Alexander V. LukyanovLftp Version3.7.1
Alexander V. LukyanovLftp Version3.7.2
Alexander V. LukyanovLftp Version3.7.3
Alexander V. LukyanovLftp Version3.7.4
Alexander V. LukyanovLftp Version3.7.5
Alexander V. LukyanovLftp Version3.7.6
Alexander V. LukyanovLftp Version3.7.7
Alexander V. LukyanovLftp Version3.7.8
Alexander V. LukyanovLftp Version3.7.9
Alexander V. LukyanovLftp Version3.7.10
Alexander V. LukyanovLftp Version3.7.11
Alexander V. LukyanovLftp Version3.7.12
Alexander V. LukyanovLftp Version3.7.13
Alexander V. LukyanovLftp Version3.7.14
Alexander V. LukyanovLftp Version4.0.0
Alexander V. LukyanovLftp Version4.0.1
Alexander V. LukyanovLftp Version4.0.2
Alexander V. LukyanovLftp Version4.0.3
Alexander V. LukyanovLftp Version4.0.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.42% 0.836
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.