CVE-2018-10201
HIGH NUCLEINComputing vSpace Pro <11 - Info Disclosure
Title source: llmDescription
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exploited remotely by a crafted URL without credentials, with .../ or ...\ or ..../ or ....\ as a directory-traversal pattern to TCP port 8667.
Exploits (1)
exploitdb
WORKING POC
by Javier Bernardo · textwebappswindows
https://www.exploit-db.com/exploits/44497
Nuclei Templates (1)
Ncomputing vSPace Pro 10 and 11 - Directory Traversal
HIGHby 0x_akoko
References (4)
Scores
CVSS v3
7.5
EPSS
0.8142
EPSS Percentile
99.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (2)
ncomputing/vspace_pro
10
ncomputing/vspace_pro
11
Published
Apr 20, 2018
Tracked Since
Feb 18, 2026