Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2001-1162

6 documents6 sources
Severity
10.0CRITICAL
EPSS
32.2%
top 3.17%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJun 23
Latest updateMay 3

Description

Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDsamba/samba6 versions+5
NVDhp/cifs-9000_servera.01.05, a.01.06+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8wh4-jc8q-39g3: Directory traversal vulnerability in the %m macro in the smb2022-05-03
CVEList
CVE-2001-1162: Directory traversal vulnerability in the %m macro in the smb2002-06-25

💥Exploits & PoCs

1
Exploit-DB
Samba 2.0.x/2.2 - Arbitrary File Creation2001-06-23

📋Vendor Advisories

1
Red Hat
security flaw2001-06-23

💬Community

1
Bugzilla
CVE-2001-1162 security flaw2018-08-16