CVE-2013-4885

medium
Published 2013-10-26 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-4885

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/drk1wi/portspoof/commit/1791fe4e2b9e5b5c8e000551ab60a64a29d924c3

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://lists.opensuse.org/opensuse-updates/2013-10/msg00030.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed6.40-0.1
debian debianbullseyefixed6.40-0.1
debian debianforkyfixed6.40-0.1
debian debiansidfixed6.40-0.1
debian debiantrixiefixed6.40-0.1
suse suse12.3affected

Application impact

VendorProductVersionsFixed
nmapnmap{"endIncluding":"6.25"}
nmapnmap2.1
nmapnmap2.2
nmapnmap2.3
nmapnmap2.05
nmapnmap2.06
nmapnmap2.07
nmapnmap2.08
nmapnmap2.09
nmapnmap2.10
nmapnmap2.11
nmapnmap2.12
nmapnmap2.50
nmapnmap2.51
nmapnmap2.52
nmapnmap2.53
nmapnmap2.54
nmapnmap2.99
nmapnmap3.00
nmapnmap3.10
nmapnmap3.15
nmapnmap3.20
nmapnmap3.25
nmapnmap3.26
nmapnmap3.27
nmapnmap3.28
nmapnmap3.30
nmapnmap3.40
nmapnmap3.45
nmapnmap3.48
nmapnmap3.50
nmapnmap3.55
nmapnmap3.70
nmapnmap3.75
nmapnmap3.81
nmapnmap3.90
nmapnmap3.91
nmapnmap3.93
nmapnmap3.94
nmapnmap3.95
nmapnmap3.96
nmapnmap3.98
nmapnmap3.99
nmapnmap3.999
nmapnmap3.9999
nmapnmap4.00
nmapnmap4.01
nmapnmap4.02
nmapnmap4.03
nmapnmap4.04
nmapnmap4.10
nmapnmap4.11
nmapnmap4.20
nmapnmap4.21
nmapnmap4.22
nmapnmap4.49
nmapnmap4.50
nmapnmap4.51
nmapnmap4.52
nmapnmap4.53
nmapnmap4.60
nmapnmap4.62
nmapnmap4.65
nmapnmap4.68
nmapnmap4.75
nmapnmap4.76
nmapnmap4.85
nmapnmap4.90
nmapnmap5.00
nmapnmap5.10
nmapnmap5.20
nmapnmap5.21
nmapnmap5.30
nmapnmap5.35
nmapnmap5.50
nmapnmap5.51
nmapnmap5.59
nmapnmap5.61
nmapnmap6.00
nmapnmap6.01
nmapnmap6.20

References

Verify integrity in audit chain (admin only). AS-IS.