Directory Traversal Vulnerability in HScripts PHP File Browser Script
CVE-2018-16549
5.3MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 5 September 2018
What is CVE-2018-16549?
The HScripts PHP File Browser Script v1.0 suffers from a directory traversal vulnerability that allows attackers to manipulate the index.php path parameter, potentially gaining unauthorized access to sensitive files on the server. This exploitation can lead to disclosure of confidential data, making it essential for users of this software to implement security measures and keep their installations updated.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published