Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-3714 PoC — node-srv 路径遍历漏洞

Source
Associated Vulnerability
Title:node-srv 路径遍历漏洞 (CVE-2018-3714)
Description:node-srv是一款支持Heroku和Grunt.js的静态Node.js服务器。 node-srv中存在路径遍历漏洞,该漏洞源于程序缺乏对url的校验。攻击者可利用该漏洞读取任意文件的内容。
Description
node-srv is vulnerable to local file inclusion due to lack of url validation, which allows a malicious user to read content of any file with known path.
File Snapshot

id: CVE-2018-3714 info: name: node-srv - Local File Inclusion author: madrobot severity: medi ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.