CVE-2014-3744
HIGH NUCLEIst module for Node.js < 0.2.5 - Path Traversal via Encoded Dot-Dot Sequences
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-3744. PoCs published by AikidoSec. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2014-3744, demonstrating a path traversal vulnerability in the 'st' Node.js module. It includes both vulnerable and protected test cases, with the latter using Aikido Security's firewall to block the attack.
Description
Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.
Exploits (1)
This repository contains a functional proof-of-concept for CVE-2014-3744, demonstrating a path traversal vulnerability in the 'st' Node.js module. It includes both vulnerable and protected test cases, with the latter using Aikido Security's firewall to block the attack.
Nuclei Templates (1)
cpe:"cpe:2.3:a:nodejs:node.js"
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N