S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-7490 Scanner

CVE-2018-7490 scanner - Directory Traversal vulnerability in uWSGI

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-7490
7.5
CVSS

uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

uWSGI is a high-performance web server and application server used to deploy and run Python and Ruby web applications. It acts as a gateway between the web server and applications, allowing the server to handle incoming web requests while the application runs separately in the background. With its ability to handle large volumes of web requests, uWSGI is a popular choice among developers for its efficiency and reliability. 

However, in January 2018, a vulnerability known as CVE-2018-7490 was discovered in uWSGI versions prior to 2.0.17, which mishandles a DOCUMENT_ROOT check during use of the --php-docroot option. This vulnerability allowed for directory traversal, enabling an attacker to access sensitive files and directories outside the intended scope of the application. 

If exploited, this vulnerability could lead to an array of dangerous consequences, such as unauthorized access to confidential data and complete system compromise. A malicious user could execute arbitrary code on the server, steal sensitive data, or even use the server as a launching point for further attacks on other systems, causing significant damage to a company's reputation and financial stability. 

As a proactive and comprehensive solution to preventing vulnerabilities such as CVE-2018-7490, s4e.io offers advanced features for continuously monitoring and scanning digital assets for potential issues. With their pro features, users can easily and quickly discover vulnerabilities in their systems and take action to prevent any attacks from occurring. Whether it's web applications or servers that are in need of protection, s4e.io provides a reliable and effective solution to keep digital assets secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken, such as:

  • Upgrading to the latest version of uWSGI (2.0.17 or above)
  • Limiting access to uWSGI to only authorized users and IP addresses
  • Ensuring that all sensitive files and directories are stored outside of the application's root directory
  • Regularly monitoring server activity for suspicious behavior
  • Implementing strong password policies and regular password changes 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-7490 scanner - Directory Traversal vulnerability in uWSGI | S4E