CVE-2019-14322

HIGH NUCLEI

Pallets Werkzeug <0.15.5 - Path Traversal

Title source: llm

Description

In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.

Exploits (4)

exploitdb WORKING POC
by faisalfs10x · pythonwebappspython
https://www.exploit-db.com/exploits/50101
nomisec WORKING POC
by sergiovks · poc
https://github.com/sergiovks/CVE-2019-14322
nomisec SCANNER
by faisalfs10x · poc
https://github.com/faisalfs10x/http-vuln-cve2019-14322.nse
nomisec SCANNER
by faisalfs10x · poc
https://github.com/faisalfs10x/CVE-2019-14322-scanner

Nuclei Templates (1)

Pallets Werkzeug <0.15.5 - Local File Inclusion
HIGHby madrobot
Shodan: cpe:"cpe:2.3:o:microsoft:windows"

Scores

CVSS v3 7.5
EPSS 0.9006
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (2)
palletsprojects/werkzeug < 0.15.5
pypi/werkzeug 0 - 0.15.5PyPI
Published Jul 28, 2019
Tracked Since Feb 18, 2026