Medium severity4.9NVD Advisory· Published Oct 3, 2017· Updated May 13, 2026
CVE-2017-9538
CVE-2017-9538
Description
The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent display of a "Cannot exit above the top directory" error message throughout the entire web application) via a ".." in the path field. In other words, the denial of service is caused by an incorrect implementation of a directory-traversal protection mechanism.
Affected products
1- cpe:2.3:a:solarwinds:network_performance_monitor:*:*:*:*:*:*:*:*Range: <=12.0.15300.90
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/101066nvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/archive/1/541263/100/0/threadednvd
News mentions
0No linked articles in our index yet.