rsync Traversal Arbitrary File Creation

Medium Nessus Plugin ID 12230


Arbitrary files may be overwritten on the remote host.


The remote rsync server might be vulnerable to a path traversal issue.

An attacker may use this flaw to gain access to arbitrary files hosted outside of a module directory.


Upgrade to rsync 2.6.1 or later.

Plugin Details

Severity: Medium

ID: 12230

File Name: rsync_path_traversal.nasl

Version: $Revision: 1.14 $

Type: remote

Family: Misc.

Published: 2004/05/06

Modified: 2016/01/15

Dependencies: 11389

Risk Information

Risk Factor: Medium


Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

Exploit Available: false

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 2004/04/30

Reference Information

CVE: CVE-2004-0426

BID: 10247

OSVDB: 5731