7.5
CVSSv3

CVE-2013-2474

Published: 27/01/2020 Updated: 29/01/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in AWS XMS 2.5 allows remote malicious users to view arbitrary files via the 'what' parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

aws-dms aws xms 2.5

Exploits

Advisory ID: HTB23147 Product: AWS XMS Vendor: wwwaws-dmscom Vulnerable Version(s): 25 and probably prior Tested Version: 25 Vendor Notification: March 6, 2013 Vendor Patch: March 16, 2013 Public Disclosure: March 27, 2013 Vulnerability Type: Path Traversal [CWE-22] CVE Reference: CVE-2013-2474 Risk Level: Medium CVSSv2 Base Score: 5 ...
AWS XMS version 25 suffers from a path traversal vulnerability ...