KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character.
AV:N/AC:L/Au:N/C:P/I:N/A:N
This vulnerability has a 8.04% probability of being exploited in the next 30 days, ranking higher than 95% of all scored CVEs.