PoC Index

CVE-2018-16716

CRITICAL 9.1EPSS 8.6%

A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in reading of arbitrary files (i.e., significant information disclosure) or file deletion via the nph-viewgif.cgi query string.

CVSS v3.0
9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
8.57% chance of exploitation in the next 30 days, 95th percentile
Nuclei
critical · CWE-22
Published
2019-05-02
Updated
2024-08-05

Nuclei templates (1)

References

Related