Description
dmmcquay.lab6 is a REST server. dmmcquay.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/dmmcquay.lab6
https://nodesecurity.io/advisories/426
Related Vulnerabilities
CVE-2023-0835 Vulnerability in npm package markdown-pdf
CVE-2021-41167 Vulnerability in npm package modern-async
CVE-2019-10754 Vulnerability in maven package org.apereo.cas:cas-server-support-oauth-core-api
CVE-2023-49145 Vulnerability in maven package org.apache.nifi:nifi-jolt-transform-json-ui
CVE-2022-24279 Vulnerability in npm package madlib-object-utils