Skip to main content

Vendor/product archive

sergey_lyubka / mongoose CVEs

Beta · best-effort

2 CVEs tagged to sergey_lyubka / mongoose0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2009-4530

Published Dec 31, 2009

Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1354

Published Apr 21, 2009

Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1