Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL path segments. Attackers can use multiple '../' sequences to navigate outside the web root and retrieve sensitive configuration files like Windows system files.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 18 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL path segments. Attackers can use multiple '../' sequences to navigate outside the web root and retrieve sensitive configuration files like Windows system files. | |
| Title | Genivia Crystal Live HTTP Server 6.01 - 'Crystal Live HTTP Server' Path Traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-18T21:54:58.491Z
Reserved: 2026-02-13T17:29:13.259Z
Link: CVE-2019-25352
No data.
Status : Received
Published: 2026-02-18T22:16:20.110
Modified: 2026-02-18T22:16:20.110
Link: CVE-2019-25352
No data.
OpenCVE Enrichment
No data.
Weaknesses