Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2017-14849

Description

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.

POC

Reference

No PoCs from references.

Github

- https://github.com/20142995/Goby

- https://github.com/20142995/nuclei-templates

- https://github.com/ARPSyndicate/cvemon

- https://github.com/ARPSyndicate/kenzer-templates

- https://github.com/CLincat/vulcat

- https://github.com/Elsfa7-110/kenzer-templates

- https://github.com/Fa1c0n35/Web-CTF-Cheatshee

- https://github.com/H4cking2theGate/TraversalHunter

- https://github.com/HimmelAward/Goby_POC

- https://github.com/JoyChou93/sks

- https://github.com/NyxAzrael/Goby_POC

- https://github.com/SLTN91/Microservices-Applications-Attack-and-Detection

- https://github.com/SexyBeast233/SecBooks

- https://github.com/Threekiii/Awesome-POC

- https://github.com/Threekiii/Vulhub-Reproduce

- https://github.com/XiaomingX/awesome-poc-for-red-team

- https://github.com/Z0fhack/Goby_POC

- https://github.com/Zxser/Web-CTF-Cheatsheet

- https://github.com/anthager/TDA602-DIT101-NodeExploit

- https://github.com/bakery312/Vulhub-Reproduce

- https://github.com/bigblackhat/oFx

- https://github.com/d4n-sec/d4n-sec.github.io

- https://github.com/duckstroms/Web-CTF-Cheatsheet

- https://github.com/heane404/CVE_scan

- https://github.com/hxysaury/saury-vulnhub

- https://github.com/ilmila/J2EEScan

- https://github.com/junwonheo/junwonheo.github.io

- https://github.com/mengdaya/Web-CTF-Cheatsheet

- https://github.com/merlinepedra/nuclei-templates

- https://github.com/merlinepedra25/nuclei-templates

- https://github.com/mrhenrike/Hacking-Cheatsheet

- https://github.com/openx-org/BLEN

- https://github.com/pwnosec/CTF-Cheatsheet

- https://github.com/q99266/saury-vulnhub

- https://github.com/qiuluo-oss/Tiger

- https://github.com/ronoski/j2ee-rscan

- https://github.com/snyk-labs/container-breaking-in-goof

- https://github.com/sobinge/nuclei-templates

- https://github.com/superfish9/pt

- https://github.com/w181496/Web-CTF-Cheatsheet