CVE-2017-20152 is a path traversal vulnerability found in the public/viewer.php component of aerouk imageserve, specifically affecting an unknown function related to file handling. By manipulating the 'filelocation' argument, an attacker can potentially access arbitrary files on the server. This vulnerability has a CVSS v3.1 score of 7.5 (HIGH), indicating a high impact on confidentiality with no integrity or availability impact. While the attack can be launched remotely with low attack complexity, the exploitability is considered difficult. Although a patch (bd23c784f0e5cb12f66d15c100248449f87d72e2) has been released and the exploit is publicly disclosed, there is no evidence of active exploitation, nor are there any known Metasploit or ExploitDB modules. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:imageserve_project:imageserve:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.