Lucene search

K
nodejs3la2kbNODEJS:772
HistoryJan 23, 2019 - 7:11 p.m.

Path Traversal

2019-01-2319:11:48
3la2kb
www.npmjs.com
15

0.004 Low

EPSS

Percentile

75.2%

Overview

Versions of http-live-simulator prior to 1.0.7 are vulnerable to Path Traversal. Due to insufficient input sanitization, attackers can access server files by using relative paths. For example: curl --path-as-is http://localhost:8080//../../../../etc/passwd.

Recommendation

Upgrade to version 1.0.7

References

CPENameOperatorVersion
http-live-simulatorle1.0.6

0.004 Low

EPSS

Percentile

75.2%