Vulnerability Details CVE-2020-27304
                The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.01
                        
                    
                    
                        
                            EPSS Ranking 76.3%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 9.8
                        
                    
                    
                        
                            CVSS v2 Score 7.5
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2020-27304
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:civetweb_project:civetweb:1.10
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:civetweb_project:civetweb:1.11
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:civetweb_project:civetweb:1.12
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:civetweb_project:civetweb:1.13
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:civetweb_project:civetweb:1.14
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:civetweb_project:civetweb:1.8
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:civetweb_project:civetweb:1.9
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:civetweb_project:civetweb:1.9.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:siemens:sinec_infrastructure_network_services:-
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:siemens:sinec_infrastructure_network_services:1.0.1