CVE-2018-16367

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
02/09/2018
Last modified:
24/08/2020

Description

In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qduoj:onlinejudge:2.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools