Описание
scott-blanch-weather-app is a sample Node.js app using Express 4. scott-blanch-weather-app is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Ссылки
- ExploitThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:scott-blanch-weather-app_project:scott-blanch-weather-app:1.0.0:*:*:*:*:node.js:*:*
EPSS
Процентиль: 67%
0.00533
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-22
CWE-22
Связанные уязвимости
CVSS3: 7.5
github
больше 5 лет назад
Directory Traversal in scott-blanch-weather-app
EPSS
Процентиль: 67%
0.00533
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-22
CWE-22