Vulnerability Database

290,278

Total vulnerabilities in the database

CVE-2018-1000161

nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.

  • Published: Apr 18, 2018
  • Updated: Apr 13, 2023
  • CVE: CVE-2018-1000161
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.7
  • AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

CVSS v2:

  • Severity: Low
  • Score: 3.5
  • AV:N/AC:M/Au:S/C:N/I:P/A:N
Software From Fixed in
nmap / nmap 6.49-beta6 6.49-beta6.x
nmap / nmap 7.00 7.00.x
nmap / nmap 7.01 7.01.x
nmap / nmap 7.10 7.10.x
nmap / nmap 7.11 7.11.x
nmap / nmap 7.12 7.12.x
nmap / nmap 7.25-beta1 7.25-beta1.x
nmap / nmap 7.25-beta2 7.25-beta2.x
nmap / nmap 7.30 7.30.x
nmap / nmap 7.31 7.31.x
nmap / nmap 7.40 7.40.x
nmap / nmap 7.50 7.50.x
nmap / nmap 7.60 7.60.x