CVE-2013-4885 - CVE House
Back to Database
Status published Medium CVE-2013-4885

The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is...

Vulnerability Description

The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-4885

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

nmap, opensuse
Vulnerable Versions:
0, 2.1, 2.2, 2.3, 2.05, 2.06, 2.07, 2.08, 2.09, 2.10, 2.11, 2.12, 2.50, 2.51, 2.52, 2.53, 2.54, 2.99, 3.00, 3.10, 3.15, 3.20, 3.25, 3.26, 3.27, 3.28, 3.30, 3.40, 3.45, 3.48, 3.50, 3.55, 3.70, 3.75, 3.81, 3.90, 3.91, 3.93, 3.94, 3.95, 3.96, 3.98, 3.99, 3.999, 3.9999, 4.00, 4.01, 4.02, 4.03, 4.04, 4.10, 4.11, 4.20, 4.21, 4.22, 4.49, 4.50, 4.51, 4.52, 4.53, 4.60, 4.62, 4.65, 4.68, 4.75, 4.76, 4.85, 4.90, 5.00, 5.10, 5.20, 5.21, 5.30, 5.35, 5.50, 5.51, 5.59, 5.61, 6.00, 6.01, 6.20, 12.3

Timeline

Official Publish: October 26th, 2013
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.