Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-6394

Опубликовано: 12 сент. 2014
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Enterprise 2nodejs010-nodejs-sendWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1146063nodejs-send: directory traversal vulnerability

EPSS

Процентиль: 89%
0.04842
Низкий

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

nvd
почти 11 лет назад

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

debian
почти 11 лет назад

visionmedia send before 0.8.4 for Node.js uses a partial comparison fo ...

github
почти 8 лет назад

Directory Traversal in send

EPSS

Процентиль: 89%
0.04842
Низкий

2.6 Low

CVSS2