cve/2018/CVE-2018-3712.md
2024-06-09 00:33:16 +00:00

781 B

CVE-2018-3712

Description

serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which allows a malicious user to view the contents of any directory with known path.

POC

Reference

Github