Vulnerabilities
Vulnerable Software
Curl:  >> Curl  >> 7.20.0  Security Vulnerabilities
curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol.
CVSS Score
7.5
EPSS Score
0.075
Published
2012-04-13
Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.
CVSS Score
5.8
EPSS Score
0.009
Published
2010-10-28


Contact Us

Shodan ® - All rights reserved