Learn about CVE-2017-10974 affecting Yaws version 1.91. Unauthorized parties can disclose remote files through an HTTP Directory Traversal attack. Find mitigation steps here.
Yaws version 1.91 has a vulnerability that allows unauthorized parties to disclose remote files through an HTTP Directory Traversal attack.
Understanding CVE-2017-10974
This CVE focuses on the exploitation of the initial /%5C sequence to bypass traversal protection mechanisms.
What is CVE-2017-10974?
The Impact of CVE-2017-10974
Technical Details of CVE-2017-10974
Yaws version 1.91 vulnerability details.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Steps to address CVE-2017-10974.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates