peter bassill · operator
$ cve CVE-2001-1162 JSON

CVE-2001-1162 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 12% (pctl 96)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS12.03% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2001-06-23
Last modified2026-06-16

Affected (2)

VendorProduct
hpcifs-9000 server
sambasamba

Public exploits

SourceTitleDate
exploit-dbSamba 2.0.x/2.2 - Arbitrary File Creation2001-06-23

References

→ the Explorer  ·  watch your stack  ·  NVD