S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 18, 2024

CVE-2011-4640 Scanner

CVE-2011-4640 scanner - Local File Inclusion (LFI) vulnerability in WebTitan

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2011-4640
4.0
CVSS

Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the fname parameter in a view action.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Vulnerability Overview

This vulnerability is present in the logs-x.php file of WebTitan, where the fname parameter is not properly sanitized. As a result, an attacker can exploit this by inserting directory traversal sequences (e.g., ../../../../../etc/passwd) to read files outside the intended directory.

Vulnerability Details

By exploiting the directory traversal vulnerability in logs-x.php, attackers can access critical system files such as /etc/passwd. The attack requires authenticated access, indicating that it could be executed by an insider or after compromising a user account. Successful exploitation could lead to sensitive information disclosure, aiding further attacks against the system.

Possible Effects

An attacker exploiting this vulnerability could achieve:

  • Unauthorized access to sensitive files, potentially including user credentials, configuration details, and private keys.
  • Gaining insights into the system structure and installed software, facilitating further targeted attacks.

Why Choose S4E

S4E offers a comprehensive suite of tools designed to identify and mitigate vulnerabilities like CVE-2011-4640. By choosing our platform, users benefit from:

  • Easy-to-use, detailed vulnerability assessments.
  • Guidance and support for remediation.
  • Continuous updates and insights into the latest security threats. Joining S4E empowers you to secure your digital environment effectively and stay ahead of cyber threats.

References

Solution Advice
  • Immediate Update: Ensure that WebTitan is updated to version 3.60 or later.
  • Review Access Controls: Verify and restrict user permissions, especially concerning file access and authentication mechanisms.
  • Monitor Activity: Implement logging and monitoring to detect unusual access patterns or exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2011-4640 scanner - Local File Inclusion (LFI) vulnerability in WebTitan | S4E