Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.
References
| Link | Resource |
|---|---|
| http://download.indusoft.com/71.2.4/IWS71.2.4.zip | |
| http://www.securityfocus.com/bid/67056 | Broken Link Third Party Advisory VDB Entry |
| https://www.cisa.gov/news-events/ics-advisories/icsa-14-107-02 | |
| https://www.exploit-db.com/exploits/42699/ | Exploit Third Party Advisory VDB Entry |
| http://ics-cert.us-cert.gov/advisories/ICSA-14-107-02 | Patch Third Party Advisory US Government Resource |
| http://www.securityfocus.com/bid/67056 | Broken Link Third Party Advisory VDB Entry |
| https://www.exploit-db.com/exploits/42699/ | Exploit Third Party Advisory VDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0780 |
Configurations
Configuration 1 (hide)
|
History
22 Oct 2025, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
25 Sep 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2014-04-25 05:12
Updated : 2025-10-22 01:15
NVD link : CVE-2014-0780
Mitre link : CVE-2014-0780
CVE.ORG link : CVE-2014-0780
JSON object : View
Products Affected
indusoft
- web_studio
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
