Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor allows remote attackers to execute arbitrary commands via an HTTP request containing (1) a .. in versions 2.0 through 2.6.18, or (2) a DOS device name followed by a .. in versions 2.6.19 through 3.0.10.
| Software | From | Fixed in |
|---|---|---|
| alchemy_lab / alchemy_eye | 2.6.19 | 2.6.19.x |
| alchemy_lab / alchemy_eye | 2.1 | 2.1.x |
| alchemy_lab / alchemy_eye | 2.6.18 | 2.6.18.x |
| alchemy_lab / alchemy_eye | 2.5 | 2.5.x |
| alchemy_lab / alchemy_eye | 3.0.10 | 3.0.10.x |
| alchemy_lab / alchemy_eye | 2.2 | 2.2.x |
| alchemy_lab / alchemy_eye | 2.3 | 2.3.x |
| alchemy_lab / alchemy_eye | 2.0 | 2.0.x |
| alchemy_lab / alchemy_eye | 2.6 | 2.6.x |
| alchemy_lab / alchemy_eye | 2.4 | 2.4.x |
| alchemy_lab / alchemy_eye | 3.0 | 3.0.x |
| dek_software / alchemy_network_monitor | - | 3.0.10.x |