PT-2018-13596 · Takeapeek · Takeapeek
Publicado
2018-11-06
·
Atualizado
2019-10-09
·
CVE-2018-16473
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
takeapeek versions <=0.2.2
takeapeek versions prior to a fixed version (no specific fixed version mentioned)
Description
A path traversal issue in the takeapeek module allows an attacker to list directories and files. All versions of takeapeek are vulnerable to this path traversal, exposing files and directories.
Recommendations
For takeapeek versions <=0.2.2, at the moment, there is no information about a newer version that contains a fix for this issue.
As a temporary workaround, consider using an alternative static file server to minimize the risk of exploitation.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Takeapeek