CVE-2017-9640
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
25/08/2017
Last modified:
20/04/2025
Description
A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:* | 5.2 (including) | |
| cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:* | 5.5 (including) | |
| cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:* | 6.0 (including) | |
| cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:* | 5.2 (including) | |
| cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:* | 5.5 (including) | |
| cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:* | 6.1 (including) | |
| cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:* | 5.2 (including) | |
| cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:* | 5.5 (including) | |
| cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:* | 6.0 (including) | |
| cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:* | 6.1 (including) |
To consult the complete list of CPE names with products and versions, see this page



