S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2017-10974 Scanner

CVE-2017-10974 scanner - Directory Traversal vulnerability in Yaws

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-10974
7.5
CVSS

Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Yaws is an open-source web server software written in Erlang programming language, designed for providing high concurrency, low latency and high performance web applications. The software's primary purpose is to act as a reverse proxy, load balancer or application server, in a variety of web and chat platforms, big and small.

CVE-2017-10974 is a vulnerability found in Yaws 1.91, which allows hackers to perform a Remote File Disclosure attack, via HTTP Directory Traversal with /%5C../ to port 8080. Directory Traversal is a vulnerability typically found in web-based applications, which can be abused to access files and directories that are otherwise prohibited by the server. The vulnerability is triggered by using the specific sequence /%5C, which goes undetected by the server.

This vulnerability can be exploited by attackers to gain unauthorized access to sensitive data that may reside on the server. As shown, the attackers can access files that are not intended for public access, such as password files, configuration files, and even source code that may contain vulnerabilities. An attacker could also leverage the file access to pivot into further attacks to compromise the server.

In conclusion, at s4e.io, we offer a platform that provides a comprehensive and easy-to-use vulnerability management solution. Our security scanning tools help identify vulnerabilities and security threats across all digital assets, enabling businesses to proactively address potential cyber-attacks. With our pro features, we can alert you of any vulnerabilities detected in your Yaws servers and offer remediation advice. Protect your digital assets with s4e.io!

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended to take the following measures:

  • Update to the latest stable version of Yaws
  • Implement access controls to limit access to sensitive information
  • Filter and validate user input to prevent malicious inputs that bypass security mechanisms
  • Monitor network traffic for anomalies or suspicious activity
  • Implement a web application firewall (WAF) to detect and block directory traversal attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.