S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 25, 2025

CVE-2025-1035 Scanner

CVE-2025-1035 Scanner - Path Traversal vulnerability in KLog Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-1035
5.7
CVSSmedium
Exploitable from an adjacent network · low-privilege account sufficient.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls. This issue affects KLog Server: before 3.1.1.

Attack Vector
Adjacent
Privileges Req.
Low
User Interaction
None
Affected
KLog Serverby Komtera Technolgies
AFFECTED< 3.1.1SAFE ✓≥ 3.1.1
Updated Aug 22, 2026View on NVD →
Detail

KLog Server is a product developed by Komtera Technologies. It is used for logging and managing system data across networks. The product is deployed in various environments to assist organizations in monitoring server activity. KLog Server processes web input to handle file system calls and log events. It is commonly used by system administrators and security professionals to track and respond to network incidents. KLog Server versions before 3.1.1 are susceptible to certain vulnerabilities that can affect system security.

The Path Traversal vulnerability in KLog Server occurs when an attacker is able to manipulate input data to traverse directories outside of the intended restricted directory. This issue can allow an attacker to access sensitive files on the server. It is triggered by a weakness in how the server processes file paths, potentially leading to unauthorized file exposure. The vulnerability affects KLog Server versions prior to 3.1.1. The risk becomes apparent when an attacker attempts to access sensitive files such as "/etc/passwd".

The vulnerability arises when the server fails to properly sanitize input provided by users during web requests. For example, an attacker can manipulate the "file" parameter in the "download.php" endpoint to include relative paths that access system files outside of the intended directory. This is an issue with how the server handles pathnames. The exploitation of this vulnerability could give attackers unauthorized access to critical system files, which can compromise the security of the system.

If exploited, this vulnerability could allow an attacker to view or download sensitive system files like "/etc/passwd", which may contain critical information such as user credentials. This can lead to further attacks, such as privilege escalation, credential theft, or other forms of system compromise. Malicious users could also gain access to configuration files and other sensitive data stored on the server, potentially leading to data breaches. If the vulnerability is left unpatched, attackers could exploit it to damage system integrity or perform unauthorized actions.

References:

Solution Advice
  • Upgrade KLog Server to version 3.1.1 or higher to resolve this vulnerability.
  • Ensure proper input sanitization is implemented for file path parameters to prevent path traversal attacks.
  • Implement additional checks to restrict file access to only authorized directories.
  • Regularly review server logs to detect any unauthorized access attempts.
  • Consider applying web application firewalls (WAFs) or intrusion detection systems (IDS) to monitor and block malicious requests.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.