CVE-2011-4518 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 26.4% (pctl 98)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 26.39% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-05-23 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsys | promotic |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsys PROMOTIC 8.1.4 - ActiveX GetPromoticSite Unitialized Pointer | 2011-10-13 |
References
→ the Explorer · watch your stack · NVD