Infodraw Media Relay Service Directory Traversal Vulnerability Allowing Arbitrary File Read

Vulnerability

A directory traversal vulnerability has been identified in Infodraw Media Relay Service (MRS) version 7.1.0.0. The issue arises in the MRS web server running on port 12654, where the username field can be manipulated to access arbitrary files by traversing directories. This vulnerability could be exploited to read the ServerParameters.xml file, which may contain administrator credentials either in cleartext or hashed with MD5.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files, including those containing administrator credentials.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.