Gleamtech FileVista Directory Traversal Vulnerability Allowing Code Execution and Privilege Escalation

Vulnerability

A directory traversal vulnerability has been identified in Gleamtech FileVista version 9.2.0.0. This vulnerability allows remote attackers to execute code, disclose information, and escalate privileges by injecting malicious payloads into HTTP requests. The exploitation involves manipulating file paths to bypass access controls and upload harmful files.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution, information disclosure, and privilege escalation on the affected system.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/filevista/fileuploader.ashx/BeginQueue' endpoint. The request must include a 'fileManagerpath' parameter that exploits the directory traversal vulnerability by navigating up the directory structure to reach the 'filevistal' directory. Once the malicious file is uploaded, it can be executed on the server, leading to code execution.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
7.5
exploitability
6.3
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.