CVE-2017-10974
HIGH EXPLOITED NUCLEIYaws - Path Traversal
Title source: ruleDescription
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.
Exploits (1)
Nuclei Templates (1)
Yaws 1.91 - Local File Inclusion
HIGHby 0x_Akoko
References (3)
Scores
CVSS v3
7.5
EPSS
0.8955
EPSS Percentile
99.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
VulnCheck KEV
2024-01-03
CWE
CWE-22
Status
published
Products (1)
yaws/yaws
1.91
Published
Jul 07, 2017
Tracked Since
Feb 18, 2026