Record summary

CVE-2016-10367 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch), an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request utilizing a simple URL encoding bypass, %252f instead of /.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 11, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHOpsview Monitor Pro - Local File InclusionCVSS 7.5

Opsview Monitor Pro prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch is vulnerable to unauthenticated local file inclusion and can be exploited by issuing a specially crafted HTTP GET request utilizing a simple bypass.

Impact

An attacker can read sensitive files on the server, potentially leading to unauthorized access or information disclosure.

Remediation

Upgrade to the latest version of Opsview Monitor Pro to fix the local file inclusion vulnerability.

WeaknessesCWE-22
Authors0x_akoko
Template tagscve2016cveopsviewlfivkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:opsview:opsview:4.5.0:*:*:*:pro:*:*:*
Shodan: title:"Opsview"
Shodan: http.title:"opsview"
FOFA: title="opsview"
Google: intitle:"opsview"

Source: ProjectDiscovery

References

2