Vulnerabilities > CVE-2005-0190 - Unspecified vulnerability in Realnetworks Realone Player and Realplayer
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN realnetworks
nessus
Summary
Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 10 |
Nessus
NASL family | Windows |
NASL id | REALPLAYER_UNDISCLOSED_VULNS.NASL |
description | According to its build number, the installed version of RealPlayer / RealOne Player for Windows may allow an attacker to execute arbitrary code and delete arbitrary files on the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15395 |
published | 2004-10-01 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15395 |
title | RealPlayer Multiple Remote Vulnerabilities (2004-09-28) |
code |
|
References
- http://marc.info/?l=bugtraq&m=109707741022291&w=2
- http://marc.info/?l=bugtraq&m=109707741022291&w=2
- http://marc.info/?l=bugtraq&m=110616160228843&w=2
- http://marc.info/?l=bugtraq&m=110616160228843&w=2
- http://secunia.com/advisories/12672/
- http://secunia.com/advisories/12672/
- http://service.real.com/help/faq/security/040928_player/EN/
- http://service.real.com/help/faq/security/040928_player/EN/
- http://www.ngssoftware.com/advisories/real-02full.txt
- http://www.ngssoftware.com/advisories/real-02full.txt
- http://www.securityfocus.com/bid/11308
- http://www.securityfocus.com/bid/11308
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17551
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17551