{"id":"CVE-2018-16493","aliases":[],"url":"https://o3.security/vulnerability/CVE-2018-16493","summary":"Path Traversal in simplehttpserver","details":"Versions of `simplehttpserver` prior to 0.2.1 are vulnerable to Path Traversal.  Due to insufficient input sanitization, attackers can access server files by using relative paths. \n\n\n## Recommendation\n\nUpgrade to version 0.2.1 or later.","published":"2019-02-07T18:18:04Z","modified":"2023-11-08T04:00:01.116915Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"static-resource-server","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-16493"},{"type":"WEB","url":"https://hackerone.com/reports/357109"},{"type":"WEB","url":"https://hackerone.com/reports/432600"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-45j8-pm75-5v8x"},{"type":"WEB","url":"https://www.npmjs.com/advisories/967"},{"type":"WEB","url":"https://www.npmjs.com/advisories/968"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:00:01.116915Z"}}