Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

David Panter

#35685of 53,634
7.5Total CVSS
Vulnerabilities · 1
PT-2018-6542
7.5
2018-01-10
Yawcam · Yawcam · CVE-2017-17662
Name of the Vulnerable Software and Affected Versions: Yawcam versions 0.2.6 through 0.6.0 Description: The issue allows attackers to read arbitrary files through a sequence of directory traversal characters. This can be achieved by using a pattern composed of one or more of either or .., such as '../' or '..../' sequences. For files with no extension, a single dot needs to be appended to the request to prevent the HTTP server from altering it. Recommendations: For Yawcam versions 0.2.6 through 0.6.0, consider restricting access to the HTTP server until a patch is available. As a temporary workaround, avoid using the HTTP server for sensitive file access.