Vulnerability Details CVE-2018-16961
An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal via the file parameter, allowing remote attackers to read PDF files in arbitrary directories.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2018-16961
-
cpe:2.3:a:buffalo:open_xdmod:3.5.0
-
cpe:2.3:a:buffalo:open_xdmod:4.5.0
-
cpe:2.3:a:buffalo:open_xdmod:4.5.1
-
cpe:2.3:a:buffalo:open_xdmod:4.5.2
-
cpe:2.3:a:buffalo:open_xdmod:5.0.0
-
cpe:2.3:a:buffalo:open_xdmod:5.5.0
-
cpe:2.3:a:buffalo:open_xdmod:5.6.0
-
cpe:2.3:a:buffalo:open_xdmod:6.5.0
-
cpe:2.3:a:buffalo:open_xdmod:6.6.0
-
cpe:2.3:a:buffalo:open_xdmod:7.0.0
-
cpe:2.3:a:buffalo:open_xdmod:7.0.1
-
cpe:2.3:a:buffalo:open_xdmod:7.1.0
-
cpe:2.3:a:buffalo:open_xdmod:7.5.0