PT-2018-13596 · Takeapeek · Takeapeek

Publicado

2018-11-06

·

Atualizado

2019-10-09

·

CVE-2018-16473

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions takeapeek versions <=0.2.2 takeapeek versions prior to a fixed version (no specific fixed version mentioned)
Description A path traversal issue in the takeapeek module allows an attacker to list directories and files. All versions of takeapeek are vulnerable to this path traversal, exposing files and directories.
Recommendations For takeapeek versions <=0.2.2, at the moment, there is no information about a newer version that contains a fix for this issue. As a temporary workaround, consider using an alternative static file server to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16473
GHSA-23XP-J737-282V

Produtos afetados

Takeapeek