{"api_version":"1","generated_at":"2026-07-23T06:38:34+00:00","cve":"CVE-2010-0620","urls":{"html":"https://cve.report/CVE-2010-0620","api":"https://cve.report/api/cve/CVE-2010-0620.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-0620","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-0620"},"summary":{"title":"CVE-2010-0620","description":"Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter.","state":"PUBLISHED","assigner":"dell","published_at":"2010-02-25 00:30:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-22","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2010/0458","name":"http://www.vupen.com/english/advisories/2010/0458","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/8230","name":"http://securityreason.com/securityalert/8230","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EMC HomeBase Server Directory Traversal Remote Code Execution  - SecurityReason.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/38380","name":"http://www.securityfocus.com/bid/38380","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"EMC HomeBase Server Directory Traversal Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/509723/100/0/threaded","name":"http://www.securityfocus.com/archive/1/509723/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-10-020/","name":"http://www.zerodayinitiative.com/advisories/ZDI-10-020/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-0620","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-0620","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"620","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"homebase_server","cpe6":"6.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"620","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"homebase_server","cpe6":"6.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:52:19.455Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"38380","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/38380"},{"name":"8230","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/8230"},{"name":"20100224 ESA-2010-003: EMC HomeBase Server Arbitrary File Upload Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/509723/100/0/threaded"},{"name":"ADV-2010-0458","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0458"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-10-020/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-02-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell"},"references":[{"name":"38380","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/38380"},{"name":"8230","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/8230"},{"name":"20100224 ESA-2010-003: EMC HomeBase Server Arbitrary File Upload Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/509723/100/0/threaded"},{"name":"ADV-2010-0458","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0458"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-10-020/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","ID":"CVE-2010-0620","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"38380","refsource":"BID","url":"http://www.securityfocus.com/bid/38380"},{"name":"8230","refsource":"SREASON","url":"http://securityreason.com/securityalert/8230"},{"name":"20100224 ESA-2010-003: EMC HomeBase Server Arbitrary File Upload Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/509723/100/0/threaded"},{"name":"ADV-2010-0458","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/0458"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-10-020/","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-10-020/"}]}}}},"cveMetadata":{"assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","assignerShortName":"dell","cveId":"CVE-2010-0620","datePublished":"2010-02-25T00:00:00.000Z","dateReserved":"2010-02-11T00:00:00.000Z","dateUpdated":"2024-08-07T00:52:19.455Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-02-25 00:30:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-22","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:emc:homebase_server:6.2:*:*:*:*:*:*:*","matchCriteriaId":"8D36EB7F-CA40-4C44-9E25-1E7AF6BB2FA9"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:homebase_server:6.3:*:*:*:*:*:*:*","matchCriteriaId":"0D186C00-9FD7-4635-B312-B6EF32855725"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"620","Ordinal":"1","Title":"CVE-2010-0620","CVE":"CVE-2010-0620","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"620","Ordinal":"1","NoteData":"Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter.","Type":"Description","Title":"CVE-2010-0620"},{"CveYear":"2010","CveId":"620","Ordinal":"2","NoteData":"2010-02-24","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"620","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}