Vulnerability Details CVE-2012-4680
Directory traversal vulnerability in the XML Server in IOServer before 1.0.19.0, when the Root Directory pathname lacks a trailing \ (backslash) character, allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in a URI.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.085
EPSS Ranking 92.0%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2012-4680
-
cpe:2.3:h:ioserver:ioserver:1.0.18.0