CVE-2016-1231
published 2016-01-12CVE-2016-1231: Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary…
PriorityP336medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
2.87%
85.2th percentile
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | prosody | < prosody 0.9.9-1 (bookworm) | prosody 0.9.9-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| prosody | prosody | — | — |
| prosody | prosody | — | — |
| prosody | prosody | — | — |
| prosody | prosody | — | — |
| prosody | prosody | — | — |
| prosody | prosody | — | — |
| prosody | prosody | — | — |
| prosody | prosody | — | — |
| prosody | prosody | — | — |
| prosody | prosody | >= 0 < 0.9.9-1 | 0.9.9-1 |
| prosody | prosody | >= 0 < 0.9.9-1 | 0.9.9-1 |
| prosody | prosody | >= 0 < 0.9.9-1 | 0.9.9-1 |
| prosody | prosody | >= 0 < 0.9.9-1 | 0.9.9-1 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-1231: prosody - Directory traversal vulnerability in the HTTP file-serving module (mod_http_file...
vendor_debian·2016·CVSS 5.9
CVE-2016-1231 [MEDIUM] CVE-2016-1231: prosody - Directory traversal vulnerability in the HTTP file-serving module (mod_http_file...
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
Scope: local
bookworm: resolved (fixed in 0.9.9-1)
bullseye: resolved (fixed in 0.9.9-1)
forky: resolved (fixed in 0.9.9-1)
sid: resolved (fixed in 0.9.9-1)
trixie: resolved (fixed in 0.9.9-1)
GHSA
GHSA-8q2g-4r27-6vpc: Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0
ghsa_unreviewed·2022-05-17
CVE-2016-1231 [MEDIUM] CWE-22 GHSA-8q2g-4r27-6vpc: Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
OSV
CVE-2016-1231: Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0
osv·2016-01-12·CVSS 5.9
CVE-2016-1231 [MEDIUM] CVE-2016-1231: Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
No detection rules found.
No public exploits indexed.
http://blog.prosody.im/prosody-0-9-9-security-release/http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175829.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175868.htmlhttp://www.debian.org/security/2016/dsa-3439http://www.openwall.com/lists/oss-security/2016/01/08/5https://prosody.im/issues/issue/520https://prosody.im/security/advisory_20160108-1/http://blog.prosody.im/prosody-0-9-9-security-release/http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175829.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175868.htmlhttp://www.debian.org/security/2016/dsa-3439http://www.openwall.com/lists/oss-security/2016/01/08/5https://prosody.im/issues/issue/520https://prosody.im/security/advisory_20160108-1/
2016-01-12
Published