CVE-2018-10201
Ncomputing vSpace Pro 10/11 - Directory Traversal
Record summary
CVE-2018-10201 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exploited remotely by a crafted URL without credentials, with .../ or ...\ or ..../ or ....\ as a directory-traversal pattern to TCP port 8667.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBNcomputing vSpace Pro 10/11 - Directory TraversalExploitDB exploitby Javier BernardoNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHNcomputing vSPace Pro 10 and 11 - Directory TraversalCVSS 7.5
Ncomputing vSpace Pro versions 10 and 11 suffer from a directory traversal vulnerability.
Impact
Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the target system.
Remediation
Apply the latest security patches or updates provided by Ncomputing to fix the directory traversal vulnerability.
Source: ProjectDiscovery