PT-2026-66884 · Rubygems · Guard-Livereload
CVE-2016-1000305
·
Publicado
2026-07-31
·
Atualizado
2026-07-31
CVSS v4.0
6.9
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
The vulnerability allows remote attackers to read arbitrary files
on the server by exploiting improper path validation in the
livereload server functionality.
This vulnerability is related to the handling of file paths in the
livereload server component, which could allow an attacker to traverse
directories and access files outside the intended web root directory.
The issue was identified and reported through the DWF (Distributed
Weakness Filing) project, which assigns CVE identifiers for
security vulnerabilities.
A directory traversal vulnerability exists in
guard-livereload before version 2.5.2.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Guard-Livereload