CVE-2014-8741
CRITICALLexmark MarkVision Enterprise <2.1 - Path Traversal
Title source: llmDescription
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotejava
https://www.exploit-db.com/exploits/35776
metasploit
WORKING POC
EXCELLENT
by Andrea Micalizzi, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/lexmark_markvision_gfd_upload.rb
Scores
CVSS v3
9.8
EPSS
0.7035
EPSS Percentile
98.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-22
Status
published
Products (1)
lexmark/markvision_enterprise
< 2.1
Published
Jan 27, 2020
Tracked Since
Feb 18, 2026