CVE-2014-9181

Plex Media Server <0.9.9.3 - Path Traversal

Title source: llm

Description

Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the URI to (1) manage/ or (2) web/ or remote authenticated users to read arbitrary files via a .. (dot dot) in the URI to resources/.

Exploits (1)

exploitdb WRITEUP
webappsmultiple
https://www.exploit-db.com/exploits/31983

Scores

EPSS 0.1530
EPSS Percentile 94.7%

Details

CWE
CWE-22
Status published
Products (1)
plex/media_server < 0.9.9.2
Published Dec 02, 2014
Tracked Since Feb 18, 2026