CVE-2014-10066

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
31/05/2018
Last modified:
13/03/2020

Description

Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacker can provide input such as `../` to read files outside of the served directory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fancy-server_project:fancy-server:*:*:*:*:*:node.js:*:* 0.1.4 (excluding)


References to Advisories, Solutions, and Tools