CVE-2019-25352
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
18/02/2026
Last modified:
19/02/2026
Description
Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL path segments. Attackers can use multiple '../' sequences to navigate outside the web root and retrieve sensitive configuration files like Windows system files.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH



