peter bassill · operator
$ cve CVE-2018-10201 JSON

CVE-2018-10201 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 44.4% (pctl 99)

Patch early

A public exploit exists.

Description

An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exploited remotely by a crafted URL without credentials, with .../ or ...\ or ..../ or ....\ as a directory-traversal pattern to TCP port 8667.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS44.42% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2018-04-20
Last modified2026-06-17

Affected (1)

VendorProduct
ncomputingvspace pro

Public exploits

SourceTitleDate
exploit-dbNcomputing vSpace Pro 10/11 - Directory Traversal2018-04-23

References

→ the Explorer  ·  watch your stack  ·  NVD