Vulnerability Details CVE-2014-10066
Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacker can provide input such as `../` to read files outside of the served directory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 76.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2014-10066
-
cpe:2.3:a:fancy-server_project:fancy-server:0.1.0
-
cpe:2.3:a:fancy-server_project:fancy-server:0.1.1
-
cpe:2.3:a:fancy-server_project:fancy-server:0.1.2
-
cpe:2.3:a:fancy-server_project:fancy-server:0.1.3