Lucene search

K

Http-file-server Security Vulnerabilities

cve
cve

CVE-2019-5447

A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.

5.3CVSS

5.2AI Score

0.001EPSS

2019-07-15 06:15 PM
27
cve
cve

CVE-2019-5458

Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.

5.4CVSS

5.4AI Score

0.001EPSS

2019-07-30 09:15 PM
32