High severity7.5NVD Advisory· Published Jul 7, 2017· Updated May 13, 2026
CVE-2017-10974
CVE-2017-10974
Description
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- hyp3rlinx.altervista.org/advisories/YAWS-WEB-SERVER-v1.91-UNAUTHENTICATED-REMOTE-FILE-DISCLOSURE.txtnvdExploitThird Party Advisory
- www.exploit-db.com/exploits/42303/nvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/99515nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.