Vulnerability Details CVE-2010-2445
freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the (1) os, (2) io, (3) package, (4) dofile, (5) loadfile, (6) loadlib, (7) module, and (8) require modules or functions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 80.9%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2010-2445
-
cpe:2.3:a:freeciv:freeciv:2.2.0
-
cpe:2.3:a:freeciv:freeciv:2.3.0