Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
boazsegev facil.io Public Folder http.c http_sendfile2 path traversal
Vulnerability Description
A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Bo facil.io 路径遍历漏洞
Vulnerability Description
boazsegev facil.io是boazsegev个人开发者的嵌入式Web服务器。 Bo facil.io 0.7.58及之前版本存在路径遍历漏洞,该漏洞源于Public Folder Handler组件中lib/facil/http/http.c文件的http_sendfile2函数存在路径遍历问题,可能导致远程攻击。
CVSS Information
N/A
Vulnerability Type
N/A