CVE-2018-17785

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
30/09/2018
Last modified:
31/12/2018

Description

In blynk-server in Blynk before 0.39.7, Directory Traversal exists via a ../ in a URI that has /static or /static/js at the beginning, as demonstrated by reading the /etc/passwd file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:blynk:blynk-server:*:*:*:*:*:*:*:* 0.39.7 (excluding)