Description
ewgaddis.lab6 is a file server. ewgaddis.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/ewgaddis.lab6
https://nodesecurity.io/advisories/465
Related Vulnerabilities
CVE-2020-7748 Vulnerability in npm package @tsed/core
CVE-2021-21388 Vulnerability in npm package systeminformation
CVE-2021-23771 Vulnerability in npm package argencoders-notevil
CVE-2022-24196 Vulnerability in maven package com.itextpdf:itext7-core
CVE-2021-41151 Vulnerability in npm package @backstage/plugin-scaffolder-backend