VDB

CVE-2011-4350

CVE-2011-4350 REJECTED

Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.

EPSS 24.95% · 96.3th percentile

Risk Scores

EPSS Score
24.95%
96.3th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSyaws0, 1.96-3, 1.97-1

Timeline

  • May 29, 2018 PoC Published
  • Nov 26, 2019 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • Apr 14, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Jul 25, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›