CVE-2018-7490
HIGH 8.7EPSS 69.4%
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
- CVSS v4.0
- 8.7 HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - CVSS v3.0
- 7.5 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.0
- 7.5 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 69.42% chance of exploitation in the next 30 days, 99th percentile
- Nuclei
- high · CWE-22
- Published
- 2018-02-26
- Updated
- 2024-08-05
Proof-of-concept exploits (1)
- qinzhu111/uWSGI-CVE-2018-7490-POC1★ · 2024-06-14
Nuclei templates (1)
ExploitDB entries (1)
Vulhub environments (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/uwsgi-cve-2018-7490.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2018/CVE-2018-7490.yaml