CVE-2018-18876

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
18/06/2019
Last modified:
18/06/2019

Description

In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:columbiaweather:weather_microserver_firmware:ms_2.6.9900:*:*:*:*:*:*:*
cpe:2.3:h:columbiaweather:weather_microserver:-:*:*:*:*:*:*:*