Owlfiles File Manager Path Traversal Vulnerability

Vulnerability

A path traversal vulnerability has been identified in Owlfiles File Manager version 12.0.1. This vulnerability resides in the application's built-in HTTP server, allowing attackers to access restricted system directories. Exploitation involves crafting GET requests that include directory traversal sequences to reach these protected directories on the device.

Impact

Exploitation of this vulnerability allows for unauthorized access to system directories, which could lead to further exploitation or exposure of sensitive information.

Reproduction

The vulnerability can be reproduced by sending a GET request to the application's HTTP server with directory traversal sequences. This request can be made using a tool like curl or through a web browser's developer tools. The server will respond with a 200 OK status and the contents of the accessed directory, demonstrating successful exploitation.

Added: Jan 13, 2026, 11:26 PM
Updated: Jan 13, 2026, 11:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.8
exploitability
8.7
remediation
0.0
relevance
2.0
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.