CVE-2016-10528

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
31/05/2018
Last modified:
09/10/2019

Description

restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Restafary before 1.6.1 is able to set up a root path, which should only allow it to run inside of that root path it specified.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:restafary_project:restafary:*:*:*:*:*:node.js:*:* 1.6.1 (excluding)


References to Advisories, Solutions, and Tools