Directory traversal vulnerability in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allows remote attackers to read and execute arbitrary files via .. (dot dot) sequences in HTTP GET or POST requests.
| Software | From | Fixed in |
|---|---|---|
| wsmp3 / wsmp3_daemon | 0.0.8 | 0.0.8.x |
| wsmp3 / wsmp3_web_server | 0.0.1 | 0.0.1.x |
| wsmp3 / wsmp3_web_server | 0.0.6 | 0.0.6.x |
| wsmp3 / wsmp3_daemon | 0.0.10 | 0.0.10.x |
| wsmp3 / wsmp3_web_server | 0.0.4 | 0.0.4.x |
| wsmp3 / wsmp3_daemon | 0.0.9 | 0.0.9.x |
| wsmp3 / wsmp3_web_server | 0.0.3 | 0.0.3.x |
| wsmp3 / wsmp3_web_server | 0.0.7 | 0.0.7.x |
| wsmp3 / wsmp3_web_server | 0.0.5 | 0.0.5.x |
| wsmp3 / wsmp3_web_server | 0.0.2 | 0.0.2.x |