CVE-2014-6394

Source
https://cve.org/CVERecord?id=CVE-2014-6394
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2014-6394.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2014-6394
Aliases
Downstream
Published
2014-10-08T17:55:05Z
Modified
2026-04-10T03:43:59.739949Z
Summary
[none]
Details

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

References

Affected packages