Total vulnerabilities in the database
visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.
Software | From | Fixed in |
---|---|---|
fedoraproject / fedora | 20 | 20.x |
fedoraproject / fedora | 21 | 21.x |
fedoraproject / fedora | 19 | 19.x |
apple / xcode | 7.0 | 7.0.x |
joyent / node.js | 0.8.2 | 0.8.2.x |
joyent / node.js | 0.8.1 | 0.8.1.x |
joyent / node.js | - | 0.8.3.x |
joyent / node.js | 0.8.0 | 0.8.0.x |
![]() |
- | 0.8.4 |