Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-6394

Опубликовано: 12 сент. 2014
Источник: redhat
CVSS2: 2.6

Описание

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Enterprise 2nodejs010-nodejs-sendWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1146063nodejs-send: directory traversal vulnerability

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

nvd
больше 10 лет назад

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

debian
больше 10 лет назад

visionmedia send before 0.8.4 for Node.js uses a partial comparison fo ...

github
больше 7 лет назад

Directory Traversal in send

2.6 Low

CVSS2