Security Advisory

CVE-2010-2627

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2010-07-02 20:00:00
Last updated 2024-09-16 19:35:26
Assigner mitre
State PUBLISHED

Description

Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.48.0) and earlier, allow remote servers to overwrite arbitrary files on the client via ".." (dot dot backslash) sequences in URLs for the (1) sponsor or (2) community logos, and other URLs related to (3) DemoDownloadURL, (4) DemoIndexURL and (5) CustomMapsURL.