CVE-2018-16716
9.1
CRITICAL · CVSS 3.0 · EPSS 8.6% (pctl 95)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in reading of arbitrary files (i.e., significant information disclosure) or file deletion via the nph-viewgif.cgi query string.
Scoring
| CVSS | 9.1 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 8.57% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-05-02 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| nih | ncbi toolbox |
References
→ the Explorer · watch your stack · NVD