PT-2020-7759 · Nhouston · Nhouston

Published

2020-08-31

·

Updated

2020-08-31

·

CVE-2014-8883

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions nhouston (affected versions not specified)
Description The issue allows an attacker to perform directory traversal by providing input such as ../ to read files outside of the served directory.
Recommendations As a temporary workaround, consider disabling the use of the nhouston module until a patch is available or an alternative module is implemented. It is recommended to use a different module, as the maintainer of nhouston has been unreachable.

Fix

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8883
GHSA-44G9-W23C-5RW7

Affected Products

Nhouston