PT-2018-13596 · Takeapeek · Takeapeek

Published

2018-11-06

·

Updated

2019-10-09

·

CVE-2018-16473

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions takeapeek versions <=0.2.2 takeapeek versions prior to a fixed version (no specific fixed version mentioned)
Description A path traversal issue in the takeapeek module allows an attacker to list directories and files. All versions of takeapeek are vulnerable to this path traversal, exposing files and directories.
Recommendations For takeapeek versions <=0.2.2, at the moment, there is no information about a newer version that contains a fix for this issue. As a temporary workaround, consider using an alternative static file server to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16473
GHSA-23XP-J737-282V

Affected Products

Takeapeek