Update CVE-2021-31800.yaml

patch-1
Prince Chaddha 2021-05-16 02:16:34 +05:30 committed by GitHub
parent 4e1c4986f8
commit 5e2eaaf7a7
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 3 additions and 3 deletions

View File

@ -1,12 +1,12 @@
id: CVE-2021-31800
info:
name: impacket directory traversal
name: Impacket directory traversal
author: geeknik
description: Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.
reference: https://github.com/SecureAuthCorp/impacket/commit/49c643bf66620646884ed141c94e5fdd85bcdd2f
reference: https://github.com/SecureAuthCorp/impacket/pull/1066
severity: high
tags: impacket,cve,cve2021,traversal
tags: impacket,cve,cve2021,lfi
requests:
- method: GET