CVE-2010-0620 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 19.5% (pctl 97)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 19.48% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-02-25 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| emc | homebase server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | EMC HomeBase Server - Directory Traversal Remote Code Execution (Metasploit) | 2011-04-27 |
References
- http://securityreason.com/securityalert/8230
- http://www.securityfocus.com/archive/1/509723/100/0/threaded
- http://www.securityfocus.com/bid/38380
- http://www.vupen.com/english/advisories/2010/0458
- http://www.zerodayinitiative.com/advisories/ZDI-10-020/
- http://securityreason.com/securityalert/8230
- http://www.securityfocus.com/archive/1/509723/100/0/threaded
- http://www.securityfocus.com/bid/38380
- http://www.vupen.com/english/advisories/2010/0458
- http://www.zerodayinitiative.com/advisories/ZDI-10-020/
→ the Explorer · watch your stack · NVD