CVE-2014-6394

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
applexcode
7.0
joyentnode.js
𝑥
≤ 0.8.3
joyentnode.js
0.8.0
joyentnode.js
0.8.1
joyentnode.js
0.8.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-send
bullseye
0.17.1-2
fixed
bookworm
0.18.0+~cs1.19.1-3
fixed
sid
1.1.0+~cs1.19.4-2
fixed
trixie
1.1.0+~cs1.19.4-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-send
disco
not-affected
cosmic
Fixed 0.9.4-1
released
bionic
Fixed 0.9.4-1
released
artful
ignored
zesty
ignored
yakkety
ignored
xenial
Fixed 0.9.4-1
released
wily
ignored
vivid
ignored
utopic
ignored
trusty
dne
precise
dne
lucid
dne
References