VYPR
Unrated severityNVD Advisory· Published Mar 15, 2023· Updated Feb 25, 2025

Roxy-WI vulnerable to Limited Path Traversal in name parameter

CVE-2023-25804

Description

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a limited path traversal vulnerability. An SSH key can be saved into an unintended location, for example the /tmp folder using a payload ../../../../../tmp/test111_dev. This issue has been fixed in version 6.3.5.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Roxy Wi/Roxy Willm-fuzzy
    Range: <6.3.5.0
  • hap-wi/roxy-wiv5
    Range: < 6.3.5.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.