Record summary

CVE-2018-10201 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exploited remotely by a crafted URL without credentials, with .../ or ...\ or ..../ or ....\ as a directory-traversal pattern to TCP port 8667.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBNcomputing vSpace Pro 10/11 - Directory TraversalExploitDB exploitby Javier BernardoNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHNcomputing vSPace Pro 10 and 11 - Directory TraversalCVSS 7.5

Ncomputing vSpace Pro versions 10 and 11 suffer from a directory traversal vulnerability.

Impact

Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the target system.

Remediation

Apply the latest security patches or updates provided by Ncomputing to fix the directory traversal vulnerability.

WeaknessesCWE-22
Authors0x_akoko
Template tagscvecve2018ncomputinglfipacketstormvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:ncomputing:vspace_pro:10:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5