CVE-2019-25087

CVSS V2 None CVSS V3 None
Description
A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri leads to path traversal: '../filedir'. The attack may be initiated remotely. The name of the patch is 1a0de56e4dafff9c2f9c8f6b130a764f7a50df52. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216863.
Overview
  • CVE ID
  • CVE-2019-25087
  • Assigner
  • cna@vuldb.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-12-27T09:15:09
  • Last Modified Date
  • 2023-01-06T05:43:42
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:httpserver_project:httpserver:*:*:*:*:*:*:*:* 1 OR 2019-09-08
History
Created Old Value New Value Data Type Notes
2022-12-27 10:14:46 Added to TrackCVE
2022-12-27 10:14:46 Weakness Enumeration new
2022-12-27 14:16:09 2022-12-27T13:48:11 CVE Modified Date updated
2022-12-27 14:16:09 Received Awaiting Analysis Vulnerability Status updated
2022-12-27 14:16:12 CVSS V3 information new
2023-01-03 19:14:31 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-03 19:14:34 CVSS V3 information new
2023-01-03 20:14:07 Undergoing Analysis Awaiting Analysis Vulnerability Status updated
2023-01-03 20:14:08 CVSS V3 information new
2023-01-04 12:15:10 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-04 12:15:12 CVSS V3 information new
2023-01-06 06:16:41 2023-01-06T05:43:42 CVE Modified Date updated
2023-01-06 06:16:41 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-06 06:16:42 Weakness Enumeration update
2023-01-06 06:16:43 CPE Information updated
2023-01-06 06:16:43 CVSS V3 information new