Description
dmmcquay.lab6 is a REST server. dmmcquay.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/dmmcquay.lab6
https://nodesecurity.io/advisories/426
Related Vulnerabilities
CVE-2021-37304 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base
CVE-2007-6433 Vulnerability in maven package org.jboss.seam:jboss-seam
CVE-2022-39230 Vulnerability in npm package fhir-works-on-aws-authz-smart
CVE-2023-31890 Vulnerability in maven package com.glazedlists:glazedlists
CVE-2021-21234 Vulnerability in maven package eu.hinsch:spring-boot-actuator-logview