CVE-2014-10073
published 2018-04-20CVE-2014-10073: The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is under the…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.26%
81.2th percentile
The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is under the webserver directory.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | psensor | < psensor 1.1.5-1 (bookworm) | psensor 1.1.5-1 (bookworm) |
| wpitchoune | psensor | < 1.1.4 | 1.1.4 |
| wpitchoune | psensor | >= 0 < 1.1.5-1 | 1.1.5-1 |
| wpitchoune | psensor | >= 0 < 1.1.5-1 | 1.1.5-1 |
| wpitchoune | psensor | >= 0 < 1.1.5-1 | 1.1.5-1 |
| wpitchoune | psensor | >= 0 < 1.1.5-1 | 1.1.5-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-54m3-4m27-xpc3: The create_response function in server/server
ghsa_unreviewed·2022-05-13
CVE-2014-10073 [HIGH] CWE-22 GHSA-54m3-4m27-xpc3: The create_response function in server/server
The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is under the webserver directory.
OSV
CVE-2014-10073: The create_response function in server/server
osv·2018-04-20·CVSS 7.5
CVE-2014-10073 [HIGH] CVE-2014-10073: The create_response function in server/server
The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is under the webserver directory.
Debian
CVE-2014-10073: psensor - The create_response function in server/server.c in Psensor before 1.1.4 allows D...
vendor_debian·2014·CVSS 7.5
CVE-2014-10073 [HIGH] CVE-2014-10073: psensor - The create_response function in server/server.c in Psensor before 1.1.4 allows D...
The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is under the webserver directory.
Scope: local
bookworm: resolved (fixed in 1.1.5-1)
bullseye: resolved (fixed in 1.1.5-1)
forky: resolved (fixed in 1.1.5-1)
sid: resolved (fixed in 1.1.5-1)
trixie: resolved (fixed in 1.1.5-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.wpitchoune.net/gitweb/?p=psensor.git%3Ba=blob%3Bf=NEWShttp://git.wpitchoune.net/gitweb/?p=psensor.git%3Ba=commit%3Bh=48739caa745f9f8002e87af574f03e5dc6ae3447http://git.wpitchoune.net/gitweb/?p=psensor.git%3Ba=commit%3Bh=8b10426dcc0246c1712a99460dd470dcb1cc4d9chttps://lists.debian.org/debian-lts-announce/2018/04/msg00026.htmlhttp://git.wpitchoune.net/gitweb/?p=psensor.git%3Ba=blob%3Bf=NEWShttp://git.wpitchoune.net/gitweb/?p=psensor.git%3Ba=commit%3Bh=48739caa745f9f8002e87af574f03e5dc6ae3447http://git.wpitchoune.net/gitweb/?p=psensor.git%3Ba=commit%3Bh=8b10426dcc0246c1712a99460dd470dcb1cc4d9chttps://lists.debian.org/debian-lts-announce/2018/04/msg00026.html
2018-04-20
Published