CVE Database
/

CVE-2018-16485

Back to search

CVE-2018-16485

Published: Feb 1, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

Path Traversal vulnerability in module m-server <1.4.1 allows malicious user to access unauthorized content of any file in the directory tree e.g. /etc/passwd by appending slashes to the URL request.

VendorProductVersions

HackerOne

m-server

affected
<1.4.1

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now