CVE-2018-10201
Ncomputing vSpace Pro 10/11 - Directory Traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exploited remotely by a crafted URL without credentials, with .../ or ...\ or ..../ or ....\ as a directory-traversal pattern to TCP port 8667.
Se ha descubierto un problema en NcMonitorServer.exe en NC Monitor Server en NComputing vSpace Pro 10 y 11. Es posible leer archivos arbitrarios fuera del directorio root del servidor web. Esta vulnerabilidad podrĂa ser explotada de forma remota por una URL manipulada sin credenciales, con .../ o ...\ o ..../ o ....\ como patrones de salto de directorio al puerto TCP 8667.
Ncomputing vSpace Pro versions 10 and 11 suffer from a directory traversal vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-04-18 CVE Reserved
- 2018-04-20 CVE Published
- 2024-02-03 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://support.ncomputing.com/portal/kb/articles/ncomputing-health-monitor-server-vulnerability-patch | X_refsource_confirm | |
https://www.kwell.net/kwell/index.php?option=com_newsfeeds&view=newsfeed&id=15&Itemid=173&lang=es | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/44497 | 2024-08-05 | |
http://www.kwell.net/kwell_blog/?p=5199 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ncomputing Search vendor "Ncomputing" | Vspace Pro Search vendor "Ncomputing" for product "Vspace Pro" | 10 Search vendor "Ncomputing" for product "Vspace Pro" and version "10" | - |
Affected
| ||||||
Ncomputing Search vendor "Ncomputing" | Vspace Pro Search vendor "Ncomputing" for product "Vspace Pro" | 11 Search vendor "Ncomputing" for product "Vspace Pro" and version "11" | - |
Affected
|