CVE-2015-5688
MEDIUM 5.0EPSS 9.4%
Directory traversal vulnerability in lib/app/index.js in Geddy before 13.0.8 for Node.js allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the PATH_INFO to the default URI.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 9.38% chance of exploitation in the next 30 days, 95th percentile
- Nuclei
- medium · CWE-22
- Published
- 2015-09-04
- Updated
- 2024-08-06