nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.
2018-04-18T19:29:00.503
2024-11-21T03:39:49.383
Modified
CVSSv3.0: 5.7 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nmap | nmap | 6.49 | Yes |
Application | nmap | nmap | 7.00 | Yes |
Application | nmap | nmap | 7.01 | Yes |
Application | nmap | nmap | 7.10 | Yes |
Application | nmap | nmap | 7.11 | Yes |
Application | nmap | nmap | 7.12 | Yes |
Application | nmap | nmap | 7.25 | Yes |
Application | nmap | nmap | 7.25 | Yes |
Application | nmap | nmap | 7.30 | Yes |
Application | nmap | nmap | 7.31 | Yes |
Application | nmap | nmap | 7.40 | Yes |
Application | nmap | nmap | 7.50 | Yes |
Application | nmap | nmap | 7.60 | Yes |