Show filters
545 Total Results
Displaying 331-340 of 545
Sort by:
Attacker Value
Unknown

CVE-2017-16146

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
mockserve is a file server. mockserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2017-16209

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
enserver is a simple web server. enserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2017-16055

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
0
Attacker Value
Unknown

CVE-2017-16038

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
`f2e-server` 1.12.11 and earlier is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. This is compounded by `f2e-server` requiring elevated privileges to run.
0
Attacker Value
Unknown

CVE-2017-16036

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
`badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2014-10066

Disclosure Date: May 31, 2018 (last updated November 26, 2024)
Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacker can provide input such as `../` to read files outside of the served directory.
Attacker Value
Unknown

CVE-2018-3733

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url, which allows a malicious user to read content of any file with known path.
Attacker Value
Unknown

CVE-2018-10389

Disclosure Date: April 02, 2018 (last updated November 27, 2024)
Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
Attacker Value
Unknown

CVE-2018-8817

Disclosure Date: March 25, 2018 (last updated November 08, 2023)
Wampserver before 3.1.3 has CSRF in add_vhost.php.
0
Attacker Value
Unknown

CVE-2018-8899

Disclosure Date: March 22, 2018 (last updated November 26, 2024)
IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations.
0