216.73.217.22

CVE-2011-10010

· Published 13/08/2025 21:15 · Modified 13/08/2025 21:15

Labels: CVE-2011-10010 2025-08-13CVE-2011-10010CWE-22[email protected]

Essential information

Published
13/08/2025 21:15
Modified
13/08/2025 21:15
Author
Creator
CVSS
9.4 CRITICAL (v3) 9.4 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

QuickShare File Server 1.2.1 contains a path traversal vulnerability in its FTP service due to improper sanitation of user-supplied file paths. Authenticated users can exploit this flaw by submitting crafted sequences to access or write files outside the intended virtual directory. When the "Writable" option is enabled (default during account creation), this allows attackers to upload arbitrary files to privileged locations such as system32, enabling remote code execution via MOF injection or executable placement.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
quickshare / quickshare file server cpe:2.3:a:quickshare:quickshare_file_server:1.2.1:*:*:*:*:*:*:*

References