Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2010-0013 — Path Traversal in Adium
Severity
7.5HIGHNVD
CNA5.0OSV5.0
EPSS
12.8%
top 5.94%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 9
Latest updateMay 2
Description
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emo…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages5 packages
Also affects: Fedora 11, 12, Linux Enterprise 11.0, Enterprise Linux 4.0, 5.0
Patches
🔴Vulnerability Details
3💥Exploits & PoCs
1📋Vendor Advisories
4Debian▶
CVE-2010-0013: pidgin - Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurp...↗2010