CVE-2012-4680

IOServer <1.0.19.0 - Path Traversal

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in the XML Server in IOServer before 1.0.19.0, when the Root Directory pathname lacks a trailing \ (backslash) character, allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in a URI.

Exploits (1)

exploitdb WRITEUP
by hinge · textwebappswindows
https://www.exploit-db.com/exploits/20677

References (3)

Core 3
Core References
Various Sources x_refsource_misc
http://www.foofus.net/?page_id=616
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50297

Scores

EPSS 0.0547
EPSS Percentile 90.3%

Details

CWE
CWE-22
Status published
Products (1)
ioserver/ioserver 1.0.18.0
Published Aug 27, 2012
Tracked Since Feb 18, 2026