Vulnerability CVE-2003-0650


Published: 2003-08-27   Modified: 2012-02-12

Description:
Directory traversal vulnerability in GSAPAK.EXE for GameSpy Arcade, possibly versions before 1.3e, allows remote attackers to overwrite arbitrary files and execute arbitrary code via .. (dot dot) sequences in filenames in a .APK (Zip) file.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Gamespy -> Arcade 

 References:
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0064.html
http://marc.info/?l=bugtraq&m=105958779017085&w=2
http://www.gamespyarcade.com/features/versions.shtml
http://www.securityfocus.com/bid/8309

Copyright 2020, cxsecurity.com

 

Back to Top