Path Traversal Vulnerability in m-server by Vendor XYZ
CVE-2018-16485
6.5MEDIUM
What is CVE-2018-16485?
The m-server product from Vendor XYZ is affected by a path traversal vulnerability that allows a malicious user to manipulate URL requests. By appending slashes, attackers can gain unauthorized access to sensitive files within the directory structure, such as system files like /etc/passwd. This vulnerability poses significant risks to data confidentiality and exposes critical information that could be exploited for further attacks.
Affected Version(s)
m-server <1.4.1