Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published: 2016-01-12T20:00:00

Updated: 2024-08-05T22:48:13.660Z

Reserved: 2015-12-27T00:00:00

Link: CVE-2016-1231

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2016-01-12T20:59:09.167

Modified: 2016-06-15T16:48:50.987

Link: CVE-2016-1231

cve-icon Redhat

No data.