e7d Speed Test (aka speedtest) 0.5.3 allows a path-traversal attack that results in information disclosure via the "GET /.." substring.
References
| Link | Resource |
|---|---|
| https://github.com/e7d/speedtest/releases | Release Notes Third Party Advisory |
| https://old.reddit.com/r/HackingTechniques/comments/poc55t/directory_traversal_bypass_on_e7d_speedtest/ | Patch Third Party Advisory |
Configurations
Information
Published : 2021-09-26 23:15
Updated : 2021-10-01 13:30
NVD link : CVE-2021-40349
Mitre link : CVE-2021-40349
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
speed_test_project
- speed_test


