Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files from the server’s filesystem. The vulnerability exists in the HTTP interface on port 4444, where the endpoint /file/ fails to properly sanitize user-supplied input. Attackers can traverse directories and access sensitive files outside the intended web root.
CVSS
No CVSS.
References
Configurations
No configuration.
History
22 Aug 2025, 18:09
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
20 Aug 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-20 16:15
Updated : 2025-08-22 18:09
NVD link : CVE-2012-10061
Mitre link : CVE-2012-10061
CVE.ORG link : CVE-2012-10061
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')