PT-2014-7207 · Visionmedia · Send
Ilya Kantor
·
Published
2014-10-08
·
Updated
2018-10-09
·
CVE-2014-6394
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
visionmedia send versions prior to 0.8.4
Description
The issue allows remote attackers to access restricted directories due to a partial comparison used for verifying whether a directory is within the document root. This can be demonstrated by accessing a "public-restricted" directory under a "public" directory.
Recommendations
Update to version 0.8.4 or later. As a temporary workaround, consider restricting access to directories that could be accessed through the vulnerable comparison.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Send