PT-2018-13596 · Takeapeek · Takeapeek
Published
2018-11-06
·
Updated
2019-10-09
·
CVE-2018-16473
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
takeapeek versions <=0.2.2
takeapeek versions prior to a fixed version (no specific fixed version mentioned)
Description
A path traversal issue in the takeapeek module allows an attacker to list directories and files. All versions of takeapeek are vulnerable to this path traversal, exposing files and directories.
Recommendations
For takeapeek versions <=0.2.2, at the moment, there is no information about a newer version that contains a fix for this issue.
As a temporary workaround, consider using an alternative static file server to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Takeapeek