- EPSS 2.77%
- Veröffentlicht 09.08.2011 20:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote attackers to execute arbitrary co...
CVE-2011-1412
- EPSS 2.38%
- Veröffentlicht 04.08.2011 02:45:32
- Zuletzt bearbeitet 11.04.2025 00:51:21
sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable...
- EPSS 5.78%
- Veröffentlicht 04.08.2011 02:45:32
- Zuletzt bearbeitet 11.04.2025 00:51:21
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which a...