Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the filename parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.088
EPSS Ranking 92.1%