← Vulnerability feed

Vulnerability record · CVE-2017-6527 · published 9 March 2017

CVE-2017-6527: dnaLIMS directory traversal in viewAppletFsa.cgi seqID parameter

Dnatools · Dnalims

dnaTools dnaLIMS 4-2015s13 is vulnerable to a NUL-terminated directory traversal attack via the seqID parameter of viewAppletFsa.cgi. An unauthenticated attacker can read system files accessible to the web server user, exposing configuration, credential or other sensitive data. The flaw is a classic path traversal (CWE-22) with a high confidentiality impact.

7.5 CVSS 3.0 High EPSS 57% · top 1.0% CWE-22 · Path traversal
7.5CVSS 3.0 base score, v2 5.0
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticated attacker to access system files readable by the web server user (by using the viewAppletFsa.cgi seqID parameter).

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated network path traversal with high confidentiality impact, public exploit code and very high EPSS, though not in KEV and no confirmed active campaigns.

What it is

dnaTools dnaLIMS 4-2015s13 is vulnerable to a NUL-terminated directory traversal attack via the seqID parameter of viewAppletFsa.cgi. An unauthenticated attacker can read system files accessible to the web server user, exposing configuration, credential or other sensitive data. The flaw is a classic path traversal (CWE-22) with a high confidentiality impact.

Impact

An attacker gains read access to any file the web server user can read, which may include application configuration, credentials or operating system files. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network through the viewAppletFsa.cgi endpoint by manipulating the seqID parameter; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N).

Exploitation

Public exploit code exists (Exploit-DB 41578 and a vendor advisory tagged Exploit), and EPSS is 0.56647 (99th percentile), indicating high likelihood of exploitation; it is not listed in CISA KEV.

What to do

  • Apply the vendor fix or upgrade dnaLIMS past version 4-2015s13 if available; no patched version is stated in the record.
  • Restrict network access to viewAppletFsa.cgi and the dnaLIMS web interface to trusted networks or a VPN.
  • Run the web server under a low-privilege account with minimal filesystem read permissions.
  • Deploy a WAF or input validation rule that rejects traversal sequences and NUL bytes in the seqID parameter.
  • Audit the web server user's file permissions and remove access to sensitive system files.

Detection

  • Monitor web logs for requests to viewAppletFsa.cgi with seqID values containing ../, ..\, %00 or encoded traversal sequences.
  • Alert on HTTP responses from viewAppletFsa.cgi returning files outside the expected application directory or unusually large responses.
  • Review file access logs for the web server user reading /etc/passwd, configuration files or other sensitive paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6527 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-6526dnaLIMS unauthenticated command execution via admin web shelldnaTools dnaLIMS 4-2015s13 exposes an improperly protected administrative web shell at cgi-bin/dna/sysAdmin.cgi that accepts POST requests without au…EPSS 57%analysed8.8CVE-2017-6529Dnatools dnalims insufficient session expiration vulnerabilityAn issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacking by guessing the UID parameter.EPSS 2.9%8.1CVE-2017-6528Dnatools dnalims insufficiently protected credentials vulnerabilityAn issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/spool/.pfile file).EPSS 3.4%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed

Source: NIST National Vulnerability Database (record CVE-2017-6527), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.