Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13296
HistoryFeb 04, 2019 - 2:25 a.m.

Directory Traversal

2019-02-0402:25:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2

0.002 Low

EPSS

Percentile

64.7%

mcstatic is vulnerable to directory traversal. The vulnerability is possible because it does not handle the file name parameter properly, allowing the attacker to read arbitrary files on the target server by appending ../ in the file path.

CPENameOperatorVersion
mcstaticle0.0.20

0.002 Low

EPSS

Percentile

64.7%