Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2010-0926

The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.382
EPSS Ranking 97.1%
CVSS Severity
CVSS v2 Score 3.5
References
Products affected by CVE-2010-0926
  • Samba » Samba » Version: 3.3.0
    cpe:2.3:a:samba:samba:3.3.0
  • Samba » Samba » Version: 3.3.1
    cpe:2.3:a:samba:samba:3.3.1
  • Samba » Samba » Version: 3.3.10
    cpe:2.3:a:samba:samba:3.3.10
  • Samba » Samba » Version: 3.3.2
    cpe:2.3:a:samba:samba:3.3.2
  • Samba » Samba » Version: 3.3.3
    cpe:2.3:a:samba:samba:3.3.3
  • Samba » Samba » Version: 3.3.4
    cpe:2.3:a:samba:samba:3.3.4
  • Samba » Samba » Version: 3.3.5
    cpe:2.3:a:samba:samba:3.3.5
  • Samba » Samba » Version: 3.3.6
    cpe:2.3:a:samba:samba:3.3.6
  • Samba » Samba » Version: 3.3.7
    cpe:2.3:a:samba:samba:3.3.7
  • Samba » Samba » Version: 3.3.8
    cpe:2.3:a:samba:samba:3.3.8
  • Samba » Samba » Version: 3.3.9
    cpe:2.3:a:samba:samba:3.3.9
  • Samba » Samba » Version: 3.4.0
    cpe:2.3:a:samba:samba:3.4.0
  • Samba » Samba » Version: 3.4.1
    cpe:2.3:a:samba:samba:3.4.1
  • Samba » Samba » Version: 3.4.2
    cpe:2.3:a:samba:samba:3.4.2
  • Samba » Samba » Version: 3.4.3
    cpe:2.3:a:samba:samba:3.4.3
  • Samba » Samba » Version: 3.4.4
    cpe:2.3:a:samba:samba:3.4.4
  • Samba » Samba » Version: 3.4.5
    cpe:2.3:a:samba:samba:3.4.5
  • Samba » Samba » Version: 3.5.0
    cpe:2.3:a:samba:samba:3.5.0


Contact Us

Shodan ® - All rights reserved