Description
dgard8.lab6 is a static file server. dgard8.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/dgard8.lab6
https://nodesecurity.io/advisories/444
Related Vulnerabilities
CVE-2021-23356 Vulnerability in npm package kill-process-by-name
CVE-2020-1938 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2017-16170 Vulnerability in npm package liuyaserver
CVE-2023-0842 Vulnerability in npm package xml2js
CVE-2022-39312 Vulnerability in maven package io.dataease:dataease-plugin-common