The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nmap | Jul 30, 2024 | Oct 26, 2013 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2 | May 29, 2017 | Oct 26, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 7, 2013 |
| Suse | — | Upgrade npingUpgrade zenmapUpgrade nmapUpgrade ndiffUpgrade ncat | Dec 12, 2013 | Oct 26, 2013 |
| Ubuntu | — | Upgrade nmap | Nov 19, 2024 | Oct 26, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub