vendor:
Mongoose
by:
Unknown
7.5
CVSS
HIGH
Remote File-Disclosure
Unknown
CWE
Product Name: Mongoose
Affected Version From: 2.8
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:cesanta:mongoose:2.8
Platforms Tested:
Unknown
Mongoose Remote File-Disclosure Vulnerability
Mongoose is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability to view the source code of files in the context of the server process, which may aid in further attacks.
Mitigation:
Unknown