Description
Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI.
Exploits (2)
References (3)
Core 3
Core References
Exploit x_refsource_misc
http://pocoftheday.blogspot.com/2009/10/mongoose-web-server-v280-remote-source_22.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/36934
Exploit, URL Repurposed x_refsource_misc
http://freetexthost.com/0lcsrgt3vw
Scores
EPSS
0.0285
EPSS Percentile
86.3%
Details
CWE
CWE-200
Status
published
Products (1)
valenok/mongoose
< 2.8.0
Published
Dec 31, 2009
Tracked Since
Feb 18, 2026