CVE-2009-2968
published 2009-09-02CVE-2009-2968: Directory traversal vulnerability in a support component in the web interface in VMware Studio 2.0 public beta before build 1017-185256 allows remote attackers…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.84%
76.5th percentile
Directory traversal vulnerability in a support component in the web interface in VMware Studio 2.0 public beta before build 1017-185256 allows remote attackers to upload files to arbitrary locations via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | studio | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-65qh-vmj5-8hx8: Directory traversal vulnerability in a support component in the web interface in VMware Studio 2
ghsa_unreviewed·2022-05-02
CVE-2009-2968 [MEDIUM] CWE-22 GHSA-65qh-vmj5-8hx8: Directory traversal vulnerability in a support component in the web interface in VMware Studio 2
Directory traversal vulnerability in a support component in the web interface in VMware Studio 2.0 public beta before build 1017-185256 allows remote attackers to upload files to arbitrary locations via unspecified vectors.
VMware
VMware Studio 2.0 addresses a security issue in the public beta version of Studio 2.0
vendor_vmware·2009-08-31·CVSS 5.0
CVE-2009-2968 [MEDIUM] VMware Studio 2.0 addresses a security issue in the public beta version of Studio 2.0
VMSA-2009-0011: VMware Studio 2.0 addresses a security issue in the public beta version of Studio 2.0
a. Directory traversal vulnerability Due to incomplete sanitation of user input, a support component of VMware Studio's web interface can be tricked into uploading a file to any directory inside the VMware Studio virtual appliance. This issue does not affect virtual machines that are created with Studio 2.0 beta. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2009-2968 to this issue. VMware would like to thank Claudio Criscione of Secure Network for reporting this issue to us. VMware Product Product Version Running on Replace with/ Apply Patch VMware Product VMware Studio Product Version 1.0 Running on VMware Replace with/ Apply Patch not affect
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2009/000064.htmlhttp://www.securityfocus.com/archive/1/506191/100/0/threadedhttp://www.securityfocus.com/bid/36199http://www.vmware.com/security/advisories/VMSA-2009-0011.htmlhttp://www.vmware.com/support/developer/studio/studio20/release_notes.htmlhttp://www.vupen.com/english/advisories/2009/2501https://exchange.xforce.ibmcloud.com/vulnerabilities/52976http://lists.vmware.com/pipermail/security-announce/2009/000064.htmlhttp://www.securityfocus.com/archive/1/506191/100/0/threadedhttp://www.securityfocus.com/bid/36199http://www.vmware.com/security/advisories/VMSA-2009-0011.htmlhttp://www.vmware.com/support/developer/studio/studio20/release_notes.htmlhttp://www.vupen.com/english/advisories/2009/2501https://exchange.xforce.ibmcloud.com/vulnerabilities/52976
2009-09-02
Published