CVE-2016-10367
opsview opsview Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2016-10367 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch), an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request utilizing a simple URL encoding bypass, %252f instead of /.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 11, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
opsviewBrowse opsview / opsview | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHOpsview Monitor Pro - Local File InclusionCVSS 7.5
Opsview Monitor Pro prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch is vulnerable to unauthenticated local file inclusion and can be exploited by issuing a specially crafted HTTP GET request utilizing a simple bypass.
Impact
An attacker can read sensitive files on the server, potentially leading to unauthorized access or information disclosure.
Remediation
Upgrade to the latest version of Opsview Monitor Pro to fix the local file inclusion vulnerability.
Source: ProjectDiscovery