A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read arbitrary files on the system with the privileges of the web server by sending crafted HTTP GET requests to the 'windows/code.php' script with a manipulated 'file' parameter. This can lead to disclosure of sensitive information.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Jul 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read arbitrary files on the system with the privileges of the web server by sending crafted HTTP GET requests to the 'windows/code.php' script with a manipulated 'file' parameter. This can lead to disclosure of sensitive information. | |
Title | RIPS Scanner v0.54 Path Traversal | |
Weaknesses | CWE-22 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-16T21:10:13.388Z
Updated: 2025-07-17T15:41:29.991Z
Reserved: 2025-04-15T19:15:22.561Z
Link: CVE-2025-34126

Updated: 2025-07-17T15:27:18.350Z

Status : Awaiting Analysis
Published: 2025-07-16T22:15:24.143
Modified: 2025-07-17T21:15:50.197
Link: CVE-2025-34126

No data.