CVE-2018-17934
23Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 20%
from disclosure to weapon0 days
Published on NVDNov 27
metasploitOct 11
exploitation probability
20%top 3% of all CVEs
observed exploitation
nono source reports it
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user, obtain restricted information, or execute arbitrary code.
Affected products
n/a · NUUO CMS