{"api_version":"1","generated_at":"2026-04-22T19:06:09+00:00","cve":"CVE-2016-15003","urls":{"html":"https://cve.report/CVE-2016-15003","api":"https://cve.report/api/cve/CVE-2016-15003.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-15003","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-15003"},"summary":{"title":"CVE-2016-15003","description":"A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects unknown code of the file C:\\Program Files\\FileZilla FTP Client\\uninstall.exe of the component Installer. The manipulation leads to unquoted search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2022-07-18 09:15:00","updated_at":"2022-07-25 18:36:00"},"problem_types":["CWE-428"],"metrics":[],"references":[{"url":"https://www.exploit-db.com/exploits/39803/","name":"https://www.exploit-db.com/exploits/39803/","refsource":"MISC","tags":[],"title":"FileZilla FTP Client 3.17.0.0 - Unquoted Path Privilege Escalation - Windows local Exploit","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://youtu.be/r06VwwJ9J4M","name":"https://youtu.be/r06VwwJ9J4M","refsource":"MISC","tags":[],"title":"Please update your browser","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://vuldb.com/?id.97204","name":"https://vuldb.com/?id.97204","refsource":"MISC","tags":[],"title":"FileZilla Client 3.17.0.0 on Windows Installer privilege escalation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-15003","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-15003","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"15003","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"filezilla-project","cpe5":"filezilla_client","cpe6":"3.17.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"15003","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2016-15003","TITLE":"FileZilla Client Installer uninstall.exe unquoted search path","REQUESTER":"cna@vuldb.com","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"generator":"vuldb.com","affects":{"vendor":{"vendor_data":[{"vendor_name":"FileZilla","product":{"product_data":[{"product_name":"Client","version":{"version_data":[{"version_value":"3.17.0.0"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-428 Unquoted Search Path"}]}]},"description":{"description_data":[{"lang":"eng","value":"A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects unknown code of the file C:\\Program Files\\FileZilla FTP Client\\uninstall.exe of the component Installer. The manipulation leads to unquoted search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used."}]},"credit":"Cyril Vallicari","impact":{"cvss":{"version":"3.1","baseScore":"6.3","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}},"references":{"reference_data":[{"url":"https://www.exploit-db.com/exploits/39803/","refsource":"MISC","name":"https://www.exploit-db.com/exploits/39803/"},{"url":"https://youtu.be/r06VwwJ9J4M","refsource":"MISC","name":"https://youtu.be/r06VwwJ9J4M"},{"url":"https://vuldb.com/?id.97204","refsource":"MISC","name":"https://vuldb.com/?id.97204"}]}},"nvd":{"publishedDate":"2022-07-18 09:15:00","lastModifiedDate":"2022-07-25 18:36:00","problem_types":["CWE-428"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:filezilla-project:filezilla_client:3.17.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":null,"notes":[]}}}