---
id: CVE-2025-34126
title: A path traversal vulnerability exists in RIPS Scanner version 0.54
summary: >-
  A path traversal vulnerability exists in RIPS Scanner version 0.54. The
  vulnerability allows remote attackers to read arbitrary files on the system
  with the privileges of the web server by sending crafted HTTP GET requests to
  the 'window…
severity: none
cwe:
  - CWE-22
published: '2025-07-16'
updated: '2026-07-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34126'
references:
  - url: >-
      https://codesec.blogspot.com/2015/03/rips-scanner-v-054-local-file-include.html
    label: disclosure@vulncheck.com
  - url: >-
      https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/scanner/http/rips_traversal.rb
    label: disclosure@vulncheck.com
  - url: 'https://rips-scanner.sourceforge.net/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/18660'
    label: disclosure@vulncheck.com
  - url: 'https://www.vulncheck.com/advisories/rips-scanner-path-traversal'
    label: disclosure@vulncheck.com
tags:
  - nvd
  - exploit-available
epss: 0.02126
epssPercentile: 0.81144
ingestedAt: '2026-07-15T13:44:02.850Z'
exploits:
  metasploit:
    - auxiliary/scanner/http/rips_traversal
  checkedAt: '2026-09-26T09:05:33.321Z'
exploitAvailable: true
---

## Overview

A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read arbitrary files on the system with the privileges of the web server by sending crafted HTTP GET requests to the 'windows/code.php' script with a manipulated 'file' parameter. This can lead to disclosure of sensitive information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
