Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-16178 1 Intsol-package Project 1 Intsol-package 2019-10-09 5.0 MEDIUM 7.5 HIGH
intsol-package is a file server. intsol-package is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16179 1 Dasafio Project 1 Dasafio 2019-10-09 5.0 MEDIUM 5.3 MEDIUM
dasafio is a web server. dasafio is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. File access is restricted to only .html files.
CVE-2017-16180 1 Serverabc Project 1 Serverabc 2019-10-09 5.0 MEDIUM 7.5 HIGH
serverabc is a static file server. serverabc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16181 1 Wintiwebdev Project 1 Wintiwebdev 2019-10-09 5.0 MEDIUM 7.5 HIGH
wintiwebdev is a static file server. wintiwebdev is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16182 1 Serverxxx Project 1 Serverxxx 2019-10-09 5.0 MEDIUM 7.5 HIGH
serverxxx is a static file server. serverxxx is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16183 1 Iter-server Project 1 Iter-server 2019-10-09 5.0 MEDIUM 7.5 HIGH
iter-server is a static file server. iter-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16184 1 Scott-blanch-weather-app Project 1 Scott-blanch-weather-app 2019-10-09 5.0 MEDIUM 7.5 HIGH
scott-blanch-weather-app is a sample Node.js app using Express 4. scott-blanch-weather-app is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16185 1 Uekw1511server Project 1 Uekw1511server 2019-10-09 5.0 MEDIUM 7.5 HIGH
uekw1511server is a static file server. uekw1511server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16186 1 360class.jansenhm Project 1 360class.jansenhm 2019-10-09 5.0 MEDIUM 7.5 HIGH
360class.jansenhm is a static file server. 360class.jansenhm is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16187 1 Open-device Project 1 Open-device 2019-10-09 5.0 MEDIUM 7.5 HIGH
open-device creates a web interface for any device. open-device is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16188 1 Reecerver Project 1 Reecerver 2019-10-09 5.0 MEDIUM 7.5 HIGH
reecerver is a web server. reecerver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16189 1 Sly07 Project 1 Sly07 2019-10-09 5.0 MEDIUM 7.5 HIGH
sly07 is an API for censoring text. sly07 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16190 1 Dcdcdcdcdc Project 1 Dcdcdcdcdc 2019-10-09 5.0 MEDIUM 7.5 HIGH
dcdcdcdcdc is a static file server. dcdcdcdcdc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16191 1 Cypserver Project 1 Cypserver 2019-10-09 5.0 MEDIUM 7.5 HIGH
cypserver is a static file server. cypserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16192 1 Getcityapi.yoehoehne Project 1 Getcityapi.yoehoehne 2019-10-09 5.0 MEDIUM 7.5 HIGH
getcityapi.yoehoehne is a web server. getcityapi.yoehoehne is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16193 1 Mfrs Project 1 Mfrs 2019-10-09 5.0 MEDIUM 7.5 HIGH
mfrs is a static file server. mfrs is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16194 1 Picard Project 1 Picard 2019-10-09 5.0 MEDIUM 7.5 HIGH
picard is a micro framework. picard is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16195 1 Pytservce Project 1 Pytservce 2019-10-09 5.0 MEDIUM 7.5 HIGH
pytservce is a static file server. pytservce is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16196 1 Quickserver Project 1 Quickserver 2019-10-09 5.0 MEDIUM 7.5 HIGH
quickserver is a simple static file server. quickserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16197 1 Qinserve Project 1 Qinserve 2019-10-09 5.0 MEDIUM 7.5 HIGH
qinserve is a static file server. qinserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16199 1 Susu-sum Project 1 Susu-sum 2019-10-09 5.0 MEDIUM 7.5 HIGH
susu-sum is a static file server. susu-sum is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16200 1 Uv-tj-demo Project 1 Uv-tj-demo 2019-10-09 5.0 MEDIUM 7.5 HIGH
uv-tj-demo is a static file server. uv-tj-demo is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16201 1 Zjjserver Project 1 Zjjserver 2019-10-09 5.0 MEDIUM 7.5 HIGH
zjjserver is a static file server. zjjserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16202 1 Cofeescript Project 1 Cofeescript 2019-10-09 5.0 MEDIUM 7.5 HIGH
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16203 1 Coffescript Project 1 Coffescript 2019-10-09 5.0 MEDIUM 7.5 HIGH
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16204 1 Jquey Project 1 Jquey 2019-10-09 5.0 MEDIUM 7.5 HIGH
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16205 1 Coffescript Project 1 Coffescript 2019-10-09 5.0 MEDIUM 7.5 HIGH
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16207 1 Discordi.js Project 1 Discordi.js 2019-10-09 5.0 MEDIUM 7.3 HIGH
discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.
CVE-2017-16208 1 Dmmcquay.lab6 Project 1 Dmmcquay.lab6 2019-10-09 5.0 MEDIUM 7.5 HIGH
dmmcquay.lab6 is a REST server. dmmcquay.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16209 1 Enserver Project 1 Enserver 2019-10-09 5.0 MEDIUM 7.5 HIGH
enserver is a simple web server. enserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16210 1 Jn Jj Server Project 1 Jn Jj Server 2019-10-09 5.0 MEDIUM 7.5 HIGH
jn_jj_server is a static file server. jn_jj_server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16211 1 Lessindex Project 1 Lessindex 2019-10-09 5.0 MEDIUM 7.5 HIGH
lessindex is a static file server. lessindex is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16212 1 Ltt Project 1 Ltt 2019-10-09 5.0 MEDIUM 7.5 HIGH
ltt is a static file server. ltt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16213 1 Mfrserver Project 1 Mfrserver 2019-10-09 5.0 MEDIUM 7.5 HIGH
mfrserver is a simple file server. mfrserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16214 1 Peiserver Project 1 Peiserver 2019-10-09 5.0 MEDIUM 7.5 HIGH
peiserver is a static file server. peiserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16215 1 Sgqserve Project 1 Sgqserve 2019-10-09 5.0 MEDIUM 7.5 HIGH
sgqserve is a simple file server. sgqserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16216 1 Tencent-server Project 1 Tencent-server 2019-10-09 5.0 MEDIUM 7.5 HIGH
tencent-server is a simple web server. tencent-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16217 1 Webrtc-experiment 1 Fbr-client 2019-10-09 5.0 MEDIUM 7.5 HIGH
fbr-client sends files through sockets via socket.io and webRTC. fbr-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16218 1 Dgard8.lab6 Project 1 Dgard8.lab6 2019-10-09 5.0 MEDIUM 7.5 HIGH
dgard8.lab6 is a static file server. dgard8.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16219 1 Yttivy Project 1 Yttivy 2019-10-09 5.0 MEDIUM 7.5 HIGH
yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16220 1 Wind-mvc Project 1 Wind-mvc 2019-10-09 5.0 MEDIUM 7.5 HIGH
wind-mvc is an mvc framework. wind-mvc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16221 1 Yzt Project 1 Yzt 2019-10-09 5.0 MEDIUM 7.5 HIGH
yzt is a simple file server. yzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16222 1 Elding Project 1 Elding 2019-10-09 5.0 MEDIUM 5.3 MEDIUM
elding is a simple web server. elding is vulnerable to a directory traversal issue, allowing an attacker to access the filesystem by placing "../" in the url. The files accessible, however, are limited to files with a file extension. Sending a GET request to /../../../etc/passwd, for example, will return a 404 on etc/passwd/index.js.
CVE-2017-16223 1 Nodeaaaaa Project 1 Nodeaaaaa 2019-10-09 5.0 MEDIUM 7.5 HIGH
nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16224 1 St Project 1 St 2019-10-09 5.8 MEDIUM 6.1 MEDIUM
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to //nodesecurity.org/%2e%2e which most browsers treat as a proper redirect as // is translated into the current schema being used. Mitigating factor: In order for this to work, st must be serving from the root of a server (/) rather than the typical sub directory (/static/) and the redirect URL will end with some form of URL encoded .. ("%2e%2e", "%2e.", ".%2e").
CVE-2017-16225 1 Aegir Project 1 Aegir 2019-10-09 5.0 MEDIUM 7.5 HIGH
aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled and published to npm the user (that performed a aegir-release) GitHub token.
CVE-2017-16226 1 Static-eval Project 1 Static-eval 2019-10-09 7.5 HIGH 9.8 CRITICAL
The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.
CVE-2017-12352 1 Cisco 1 Application Policy Infrastructure Controller 2019-10-09 7.2 HIGH 6.7 MEDIUM
A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an authenticated, local attacker to gain elevated privileges and execute arbitrary commands with root privileges on an affected host operating system. The vulnerability is due to insufficient validation of user-controlled input that is supplied to certain script files of an affected system. An attacker could exploit this vulnerability by submitting crafted input to a script file on an affected system. A successful exploit could allow the attacker to gain elevated privileges and execute arbitrary commands with root privileges on the affected system. To exploit this vulnerability, the attacker would need to authenticate to the affected system by using valid administrator credentials. Cisco Bug IDs: CSCvf57274.
CVE-2017-12353 1 Cisco 1 Asyncos 2019-10-09 5.0 MEDIUM 5.8 MEDIUM
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. The vulnerability is due to improper error handling of a malformed MIME header in an email attachment. An attacker could exploit this vulnerability by sending an email with a crafted MIME attachment. For example, a successful exploit could allow the attacker to bypass configured user filters to drop the email. The malformed MIME headers may not be RFC compliant. However, some mail clients could still allow users to access the attachment, which may not have been properly filtered by the device. Cisco Bug IDs: CSCvf44666.
CVE-2017-12354 1 Cisco 1 Secure Access Control System 2019-10-09 5.0 MEDIUM 5.3 MEDIUM
A vulnerability in the web-based interface of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not sufficiently protect system software version information when the software responds to HTTP requests that are sent to the web-based interface of the software. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based interface of the affected software. A successful exploit could allow the attacker to view sensitive information about the software, which the attacker could use to conduct additional reconnaissance attacks. Cisco Bug IDs: CSCvf66155.