CVE-2009-4530
Published Dec 31, 2009Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI.
Vendor/product archive
2 CVEs tagged to sergey_lyubka / mongoose — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI.
Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.