Description
Directory traversal vulnerability in download.py in Pyplate 0.08 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
References (2)
Core 2
Core References
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/05/23/1
Exploit mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/05/14/3
Scores
EPSS
0.0180
EPSS Percentile
75.9%
Details
CWE
CWE-22
Status
published
Products (1)
pyplate/pyplate
0.08
Published
Aug 07, 2014
Tracked Since
Feb 18, 2026