Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
static-server 路径遍历漏洞
Vulnerability Description
statics-server是一款用于收集Joomla安装环境信息的服务器。 static-server 存在路径遍历漏洞,该漏洞源于通过 server.js 的 validPath 函数传递的输入清理不当,导致容易受到目录遍历的攻击。
CVSS Information
N/A
Vulnerability Type
N/A