Security Advisory

CVE-2018-25178

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-03-06 12:19:08
Last updated 2026-03-09 19:00:55
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the file parameter. Attackers can send POST requests to showtif.php with arbitrary file paths in the file parameter to retrieve system files like configuration and initialization files.