Description
desafio is a simple web server. desafio is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url, but is limited to accessing only .html files.
Remediation
References
https://nodesecurity.io/advisories/397
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/desafio
Related Vulnerabilities
CVE-2020-6452 Vulnerability in npm package electron
CVE-2019-10447 Vulnerability in maven package io.jenkins.plugins:sofy-ai
CVE-2018-7560 Vulnerability in npm package aws-lambda-multipart-parser
CVE-2015-8031 Vulnerability in maven package org.jvnet.hudson.main:hudson-core
CVE-2018-18531 Vulnerability in maven package com.github.penggle:kaptcha