Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL path segments. Attackers can use multiple '../' sequences to navigate outside the web root and retrieve sensitive configuration files like Windows system files.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Genivia
Genivia crystal Live Http Server |
|
| Vendors & Products |
Genivia
Genivia crystal Live Http Server |
Wed, 18 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL path segments. Attackers can use multiple '../' sequences to navigate outside the web root and retrieve sensitive configuration files like Windows system files. | |
| Title | Genivia Crystal Live HTTP Server 6.01 - 'Crystal Live HTTP Server' Path Traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-18T21:54:58.491Z
Reserved: 2026-02-13T17:29:13.259Z
Link: CVE-2019-25352
No data.
Status : Received
Published: 2026-02-18T22:16:20.110
Modified: 2026-02-18T22:16:20.110
Link: CVE-2019-25352
No data.
OpenCVE Enrichment
Updated: 2026-02-19T10:10:50Z