5
CVSSv2

CVE-2010-4181

Published: 04/11/2010 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in Yaws 1.89 allows remote malicious users to read arbitrary files via ..\ (dot dot backslash) and other sequences.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yaws yaws 1.89

Exploits

# Exploit Title: Yaws 189 Directory Traversal # Date: 29 Oct # Author: nitr0us (Alejandro Hernandez H) # Software Link: yawshyberorg/download/Yaws-189-windows-installerexe # Version: 189 # Tested on: Windows XP Service Pack 2 Chatsubo [(in)Security Dark] Labs chatsubo-labsblogspotcom wwwbrainoverfloworg EXPLOIT: ** ...