AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2010-2251

HIGH · CVSS 7.5 EPSS 3.63%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2010-07-06 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2010-2251
Severity
HIGH
CVSS
7.5
EPSS
3.63%

Original NVD Description

The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.