Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8q2g-4r27-6vpc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.

Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.

EPSS

Процентиль: 72%
0.00741
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 10 лет назад

Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.

CVSS3: 5.9
nvd
около 10 лет назад

Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.

CVSS3: 5.9
debian
около 10 лет назад

Directory traversal vulnerability in the HTTP file-serving module (mod ...

EPSS

Процентиль: 72%
0.00741
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-22