S4E just found a high-severity finding from cve-2025-14675 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 7, 2024

CVE-2016-10367 Scanner

Detects 'Local File Inclusion (LFI)' vulnerability in Opsview Monitor Pro affects v. (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2016-10367
7.5
CVSS

In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch), an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request utilizing a simple URL encoding bypass, %252f instead of /.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Opsview Monitor Pro is a monitoring and alerting tool designed for IT infrastructure. This product is commonly used in enterprises to monitor their critical servers and applications. Opsview offers a single view of the IT infrastructure through comprehensive dashboards, making it easier for IT teams to proactively detect and resolve issues in real-time.

CVE-2016-10367 is an unauthenticated Directory Traversal vulnerability discovered in Opsview Monitor Pro. This vulnerability is caused by a lack of input validation when parsing URL-encoded strings containing directory traversal sequences. Attackers can exploit this by sending specially crafted HTTP GET requests utilizing a simple URL encoding bypass, %252f instead of /, to execute arbitrary code.

Exploitation of the CVE-2016-10367 vulnerability represents a severe risk to organizations using Opsview Monitor Pro. Attackers who successfully exploit this vulnerability can access sensitive information within an organization, modify or delete data, or even execute remote code on affected systems. This could result in service disruption, data theft, or other nefarious activities, leading to negative economic impact and reputational damage.

In conclusion, security is a critical part of any organization's digital assets. Thanks to the pro features of the s4e.io platform, users can explore and learn about the vulnerabilities in their digital assets and implement the necessary precautions to protect against them. By following best practices for security, organizations can minimize their attack surface and maintain a secure and resilient IT infrastructure.

 

REFERENCES

Solution Advice

To protect against the CVE-2016-10367 vulnerability, users of Opsview Monitor Pro should perform the following actions:

  • Upgrade to the latest version of Opsview that includes the security patch.
  • Ensure that all directory traversal sequences within HTTP GET requests are properly sanitized.
  • Consider implementing network controls, such as firewalls, to restrict the webserver's access to sensitive information and resources.
  • Regularly scan all IT systems for vulnerabilities using security scanning tools and ensure that patches and updates are promptly installed.
  • Implement network and host-based intrusion detection systems to detect and alert on any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2016-10367 scanner - Local File Inclusion (LFI) vulnerability in Opsview Monitor Pro | S4E