CVE-2017-16198

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
07/06/2018
Last modified:
19/07/2018

Description

ritp is a static web server. ritp is vulnerable to a directory traversal issue whereby an attacker can gain access to the file system by placing ../ in the URL. Access is restricted to files with a file extension, so files such as /etc/passwd are not accessible.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ritp_project:ritp:1.0.2:*:*:*:*:node.js:*:*
cpe:2.3:a:ritp_project:ritp:1.0.3:*:*:*:*:node.js:*:*
cpe:2.3:a:ritp_project:ritp:1.0.4:*:*:*:*:node.js:*:*
cpe:2.3:a:ritp_project:ritp:1.0.5:*:*:*:*:node.js:*:*