PT-2025-29888 · Unknown · Rips Scanner

Localh0T

·

Published

2025-07-16

·

Updated

2025-07-17

·

CVE-2025-34126

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions RIPS Scanner version 0.54
Description A path traversal vulnerability exists that allows remote attackers to read arbitrary files on the system with the privileges of the web server. This is achieved by sending crafted HTTP GET requests to the /windows/code.php script with a manipulated file parameter, potentially leading to disclosure of sensitive information.
Recommendations For RIPS Scanner version 0.54, avoid using the file parameter in the /windows/code.php script. As a temporary workaround, consider restricting access to the windows/code.php script until a patch is available.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-34126

Affected Products

Rips Scanner