vendor:
Crystal Quality
by:
Numan Türle
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Crystal Quality
Affected Version From: 06.01
Affected Version To: 06.01
Patch Exists: NO
Related CWE:
CPE: Crystal Live HTTP Server 6.01
Platforms Tested:
2019
Crystal Live HTTP Server 6.01 – Directory Traversal
The Crystal Live HTTP Server 6.01 is vulnerable to directory traversal. By sending a specially crafted GET request, an attacker can access files outside the web root directory.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the Crystal Live HTTP Server.