CVE-2008-7110

Kyocera Mita Scanner File Utility 3.3.0.1 - Path Traversal via Dot-Dot in Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-7110. PoCs published by Seth Fogie.

AI-analyzed exploit summary This exploit targets a directory traversal vulnerability in Kyocera Mita Scanner File Utility 3.3.0.1, allowing arbitrary file creation/overwrite. It includes a scanner to detect valid account IDs and passwords, and a payload delivery mechanism to upload files with arbitrary paths.

Description

Directory traversal vulnerability in the Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to upload files to arbitrary locations via a .. (dot dot) in a request.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Seth Fogie · pythonremotewindows
https://www.exploit-db.com/exploits/32301

This exploit targets a directory traversal vulnerability in Kyocera Mita Scanner File Utility 3.3.0.1, allowing arbitrary file creation/overwrite. It includes a scanner to detect valid account IDs and passwords, and a payload delivery mechanism to upload files with arbitrary paths.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Kyocera Mita Scanner File Utility 3.3.0.1
No auth needed
Prerequisites: Network access to TCP port 37100 · Target software installed and running
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/495772/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44718
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30855
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31631

Scores

EPSS 0.0288
EPSS Percentile 85.1%

Details

CWE
CWE-22
Status published
Products (1)
kyoceramita/scanner_file_utility 3.3.0.1
Published Aug 28, 2009
Tracked Since Feb 18, 2026