CVE-2011-4350
MEDIUMYaws 1.91 - Authenticated Path Traversal via URL Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-4350.
PoCs published by sinn3r, including Metasploit module auxiliary/scanner/http/yaws_traversal.
AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability in Yaws web server (v1.9.1 or less) to retrieve arbitrary files. It sends a crafted GET request with traversal sequences to access files outside the web root.
Description
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.
Exploits (1)
This Metasploit module exploits a directory traversal vulnerability in Yaws web server (v1.9.1 or less) to retrieve arbitrary files. It sends a crafted GET request with traversal sequences to access files outside the web root.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N