Critical severity9.9OSV Advisory· Published Sep 2, 2018· Updated Jun 17, 2026
CVE-2018-16367
CVE-2018-16367
Description
In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3beta-2.0+ 1 more
- (no CPE)range: beta-2.0
- (no CPE)range: = 2.0
- cpe:2.3:a:qduoj:onlinejudge:2.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/QingdaoU/OnlineJudge/issues/165nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.