header-logo
Suggest Exploit
vendor:
cURL
by:
Secunia Research
8.8
CVSS
HIGH
Security-Bypass
20
CWE
Product Name: cURL
Affected Version From: 5.11
Affected Version To: 7.19.3
Patch Exists: YES
Related CWE: CVE-2009-0037
CPE: 20
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009

cURL/libcURL Security-Bypass Vulnerability

Remote attackers can exploit this issue to bypass certain security restrictions and carry out various attacks. The following example redirection request may be used to carry out this attack: Location: scp://name:passwd@host/a'``;date >/tmp/test``;'

Mitigation:

Upgrade to version 7.19.4 or later.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/33962/info

cURL/libcURL is prone to a security-bypass vulnerability.

Remote attackers can exploit this issue to bypass certain security restrictions and carry out various attacks.

This issue affects cURL/libcURL 5.11 through 7.19.3. Other versions may also be vulnerable.

The following example redirection request may be used to carry out this attack:
Location: scp://name:passwd@host/a'``;date >/tmp/test``;'