CVE-2013-1627: Path Traversal
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via a full pathname in an argument to the sub401A90 CreateFileW function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1627?
CVE-2013-1627 is rated as a medium severity vulnerability.
How does CVE-2013-1627 operate?
CVE-2013-1627 allows remote attackers to read arbitrary files using a full pathname due to an absolute path traversal vulnerability.
Which software is affected by CVE-2013-1627?
CVE-2013-1627 affects InduSoft Studio versions 7.0 and earlier, as well as Advantech Studio versions 7.0 and earlier.
How do I fix CVE-2013-1627?
To mitigate CVE-2013-1627, it is recommended to update to the latest version of the affected software, if available.
Is CVE-2013-1627 exploitable remotely?
Yes, CVE-2013-1627 can be exploited by remote attackers, making it critical to secure affected systems.