S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-16716 Scanner

CVE-2018-16716 scanner - Path Traversal vulnerability in NCBI ToolBox

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-16716
9.1
CVSS

A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in reading of arbitrary files (i.e., significant information disclosure) or file deletion via the nph-viewgif.cgi query string.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The NCBI ToolBox is a software suite used by researchers in the field of bioinformatics. It enables scientists to analyze and manipulate large amounts of genetic data, aiding in the understanding and discovery of new biological insights. The software is widely used across the academic and scientific industries and is an invaluable resource for many researchers seeking to decode the mysteries of the human genome.

Unfortunately, the NCBI ToolBox is not without its flaws. One such vulnerability is the CVE-2018-16716, a path traversal vulnerability in viewcgi.c. This vulnerability can be exploited by attackers to gain access to arbitrary files on a victim machine, resulting in significant information disclosure or even file deletion via the nph-viewgif.cgi query string.

The consequences of CVE-2018-16716 are severe. Attackers can use the vulnerability to access confidential data, including sensitive financial information, personal identification data, and research results. Such data breaches can cause significant financial, legal, and reputational damage to affected organizations, and can take months or even years to recover from.

Thankfully, with the pro features of the s4e.io platform, organizations can quickly and easily learn about vulnerabilities in their digital assets. This powerful tool can detect and monitor vulnerabilities across a wide range of systems, from web applications to mobile devices, allowing organizations to take proactive steps to protect their critical data and systems from cyber attacks. By using this platform, organizations can stay one step ahead of attackers and protect their stakeholders from the devastating effects of data breaches.

 

REFERENCES

Solution Advice

To protect against CVE-2018-16716, organizations must take proactive steps, including regularly updating software, monitoring system logs for suspicious activity, and restricting access to sensitive data and systems. Other precautions that can be taken include:

  • Regularly scanning software for vulnerabilities and patching them as soon as they are discovered.
  • Implementing strong authentication and access control mechanisms, such as two-factor authentication and biometric scanning.
  • Segmenting sensitive data and systems from less critical systems and implementing strong network security measures, such as firewalls and intrusion detection systems.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.