A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows. Affected by this vulnerability is an unknown functionality of the file \EasySpider\resources\app\server.js of the component HTTP GET Request Handler. The manipulation with the input /../../../../../../../../../Windows/win.ini leads to path traversal: '../filedir'. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The identifier VDB-271477 was assigned to this vulnerability. NOTE: The code maintainer explains, that this is not a big issue "because the default is that the software runs locally without going through the Internet".
References
Link | Resource |
---|---|
https://vuldb.com/?id.271477 | Third Party Advisory VDB Entry |
https://vuldb.com/?ctiid.271477 | Permissions Required |
https://vuldb.com/?submit.371998 | Third Party Advisory VDB Entry |
https://github.com/NaiboWang/EasySpider/issues/466 | Exploit Issue Tracking |
Configurations
Configuration 1 (hide)
AND |
|
History
19 Jul 2024, 18:02
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
First Time |
Microsoft windows
Easyspider easyspider Easyspider Microsoft |
|
CPE | cpe:2.3:a:easyspider:easyspider:0.6.2:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
CWE | CWE-22 | |
References | () https://vuldb.com/?id.271477 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?ctiid.271477 - Permissions Required | |
References | () https://vuldb.com/?submit.371998 - Third Party Advisory, VDB Entry | |
References | () https://github.com/NaiboWang/EasySpider/issues/466 - Exploit, Issue Tracking |
15 Jul 2024, 13:00
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-15 12:15
Updated : 2024-07-19 18:02
NVD link : CVE-2024-6746
Mitre link : CVE-2024-6746
JSON object : View
Products Affected
easyspider
- easyspider
microsoft
- windows
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')