PT-2014-7207 · Visionmedia · Send

Ilya Kantor

·

Publicado

2014-10-08

·

Atualizado

2018-10-09

·

CVE-2014-6394

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions visionmedia send versions prior to 0.8.4
Description The issue allows remote attackers to access restricted directories due to a partial comparison used for verifying whether a directory is within the document root. This can be demonstrated by accessing a "public-restricted" directory under a "public" directory.
Recommendations Update to version 0.8.4 or later. As a temporary workaround, consider restricting access to directories that could be accessed through the vulnerable comparison.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-6394
GHSA-PGV6-JRVV-75JP
GHSA-XWG4-93C6-3H42

Produtos afetados

Send