Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Maybe-Why-Not

#18098of 53,622
15Total CVSS
Vulnerabilities · 2
High
2
PT-2022-12003
7.5
2022-04-04
Caucho · Caucho Resin · CVE-2021-44138
**Name of the Vulnerable Software and Affected Versions** Caucho Resin versions 4.0.52 through 4.0.56 **Description** The issue allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request. This is a Directory traversal vulnerability. **Recommendations** For versions 4.0.52 through 4.0.56, consider restricting access to sensitive directories and files as a temporary workaround until a patch is available. Avoid using the ; character in pathnames within HTTP requests to minimize the risk of exploitation.
PT-2021-18660
7.5
2021-01-05
Unknown · Ffay Lanproxy · CVE-2021-3019
**Name of the Vulnerable Software and Affected Versions** ffay lanproxy version 0.1 **Description** The issue allows Directory Traversal, enabling the reading of `/../conf/config.properties` to obtain credentials for a connection to the intranet. This could potentially expose sensitive information. **Recommendations** For ffay lanproxy version 0.1, consider restricting access to the `/../conf/config.properties` file until a patch is available. As a temporary workaround, limit the exposure of sensitive credentials stored in this file. At the moment, there is no information about a newer version that contains a fix for this vulnerability.