CVE-2018-10201 EXPLOIT
7.5
HIGH · CVSS 3.0 · EPSS 44.4% (pctl 99)
Patch early
A public exploit exists.
Description
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exploited remotely by a crafted URL without credentials, with .../ or ...\ or ..../ or ....\ as a directory-traversal pattern to TCP port 8667.
Scoring
| CVSS | 7.5 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 44.42% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-04-20 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| ncomputing | vspace pro |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ncomputing vSpace Pro 10/11 - Directory Traversal | 2018-04-23 |
References
- http://www.kwell.net/kwell_blog/?p=5199
- https://support.ncomputing.com/portal/kb/articles/ncomputing-health-monitor-server-vulnerability-patch
- https://www.exploit-db.com/exploits/44497/
- https://www.kwell.net/kwell/index.php?option=com_newsfeeds&view=newsfeed&id=15&Itemid=173&lang=es
- http://www.kwell.net/kwell_blog/?p=5199
- https://support.ncomputing.com/portal/kb/articles/ncomputing-health-monitor-server-vulnerability-patch
- https://www.exploit-db.com/exploits/44497/
- https://www.kwell.net/kwell/index.php?option=com_newsfeeds&view=newsfeed&id=15&Itemid=173&lang=es
→ the Explorer · watch your stack · NVD