7.5
CVSSv2

CVE-2010-0533

Published: 30/03/2010 Updated: 10/09/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 780
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in AFP Server in Apple Mac OS X prior to 10.6.3 allows remote malicious users to list a share root's parent directory, and read and modify files in that directory, via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x server

apple mac os x 10.6.1

apple mac os x server 10.6.0

apple mac os x 10.6.0

apple mac os x

apple mac os x server 10.6.1

Nmap Scripts

afp-path-vuln

Detects the Mac OS X AFP directory traversal vulnerability, CVE-2010-0533.

nmap -sV --script=afp-path-vuln <target>

PORT STATE SERVICE 548/tcp open afp | afp-path-vuln: | VULNERABLE: | Apple Mac OS X AFP server directory traversal | State: VULNERABLE (Exploitable) | IDs: CVE:CVE-2010-0533 | Risk factor: High CVSSv2: 7.5 (HIGH) (AV:N/AC:L/Au:N/C:P/I:P/A:P) | Description: | Directory traversal vulnerability in AFP Server in Apple Mac OS X before | 10.6.3 allows remote attackers to list a share root's parent directory. | Disclosure date: 2010-03-29 | Exploit results: | Patrik Karlsson's Public Folder/../ (5 first items) | .bash_history | .bash_profile | .CFUserTextEncoding | .config/ | .crash_report_checksum | References: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0533 | http://support.apple.com/kb/HT1222 |_ http://www.cqure.net/wp/2010/03/detecting-apple-mac-os-x-afp-vulnerability-cve-2010-0533-with-nmap
afp-path-vuln

Detects the Mac OS X AFP directory traversal vulnerability, CVE-2010-0533.

nmap -sV --script=afp-path-vuln <target>

PORT STATE SERVICE 548/tcp open afp | afp-path-vuln: | VULNERABLE: | Apple Mac OS X AFP server directory traversal | State: VULNERABLE (Exploitable) | IDs: CVE:CVE-2010-0533 | Risk factor: High CVSSv2: 7.5 (HIGH) (AV:N/AC:L/Au:N/C:P/I:P/A:P) | Description: | Directory traversal vulnerability in AFP Server in Apple Mac OS X before | 10.6.3 allows remote attackers to list a share root's parent directory. | Disclosure date: 2010-03-29 | Exploit results: | Patrik Karlsson's Public Folder/../ (5 first items) | .bash_history | .bash_profile | .CFUserTextEncoding | .config/ | .crash_report_checksum | References: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0533 | http://support.apple.com/kb/HT1222 |_ http://www.cqure.net/wp/2010/03/detecting-apple-mac-os-x-afp-vulnerability-cve-2010-0533-with-nmap