vendor:
Yaws v1.91 (Yet Another Web Server)
by:
John Page aka hyp3rlinx
7,5
CVSS
HIGH
Unauthenticated Remote File Disclosure
200
CWE
Product Name: Yaws v1.91 (Yet Another Web Server)
Affected Version From: v1.91
Affected Version To: v1.91
Patch Exists: YES
Related CWE: CVE-2017-10974
CPE: a:yaws:yaws:1.91
Metasploit:
N/A
Other Scripts:
N/A
Tags: edb,cve,cve2017,yaws,lfi
CVSS Metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Nuclei Metadata: {'max-request': 1, 'vendor': 'yaws', 'product': 'yaws'}
Platforms Tested: None
2017
YAWS-WEB-SERVER-v1.91-UNAUTHENTICATED-REMOTE-FILE-DISCLOSURE
Yaws 1.91 allows unauthenticated local file inclusion via /%5C../ submitted to port 8080.
Mitigation:
Upgrade to the latest version of Yaws.