Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses >> CherryPy staticFilter Directory Traversal Vulnerability


Vulnerability Assessment Details

CherryPy staticFilter Directory Traversal Vulnerability

Vulnerability Assessment Summary
Checks for staticFilter directory traversal vulnerability in CherryPy

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote web server is prone to directory traversal attacks.

Description :

The remote host is running CherryPy, a web server powered by Python.

The installed version of CherryPy fails to filter directory traversal
sequences from requests that pass through its 'staticFilter' module.
A possible hacker can exploit this issue to read arbitrary files on the
remote host subject to the rights under which the affected
application runs.

See also :

http://www.nessus.org/u?11e78d5a

Solution :

Upgrade to CherryPy version 2.1.1 or later.

Network Security Threat Level:

Low / CVSS Base Score : 2.3
(AV:R/AC:L/Au:NR/C:P/I:N/A:N/B:N)

Networks Security ID: 16760

Vulnerability Assessment Copyright: This script is Copyright (C) 2006 Tenable Network Security

Cables, Connectors


2024 Lenovo IdeaPad Laptop Notebook 15.6

2024 Lenovo IdeaPad Laptop Notebook 15.6" Intel Processor Upto 20GB RAM 1TB SSD

$239.00



Lenovo LOQ 15.6

Lenovo LOQ 15.6" FHD 144Hz Gaming Notebook R7-7435HS 16GB RAM 512GB SSD RTX 4070

$899.99



Lenovo Yoga 6th Gen ThinkPad 11e 2-in-1 Laptop Windows 11 Pro. 8GB RAM 256GB SSD picture

Lenovo Yoga 6th Gen ThinkPad 11e 2-in-1 Laptop Windows 11 Pro. 8GB RAM 256GB SSD

$94.00



Lenovo - IdeaPad 1 15.6

Lenovo - IdeaPad 1 15.6" (FHD) Laptop - AMD Ryzen 3 - AMD Radeon - 4GB - 128...

$249.99



Lenovo IdeaPad Slim 3 15.6

Lenovo IdeaPad Slim 3 15.6" Touchscreen FHD AMD Ryzen 5 7530U 16GB 512GB SSD W11

$299.00



Lenovo LOQ 15.6

Lenovo LOQ 15.6" FHD 144Hz Gaming Notebook R7-7435HS 16GB RAM 512GB SSD RTX 4050

$719.99



Lenovo N23 Yoga Touchscreen  Chromebook 11.6

Lenovo N23 Yoga Touchscreen Chromebook 11.6" 4GB RAM 32GB eMMc With Charger

$38.00



Lenovo 100W Gen 3 Laptop – Open BOX – Model 82HY – WIN 11 picture

Lenovo 100W Gen 3 Laptop – Open BOX – Model 82HY – WIN 11

$99.00



Lenovo Desktop i5 Computer PC SFF Up To 32GB RAM 1TB SSD Windows 10 Pro Wi-Fi picture

Lenovo Desktop i5 Computer PC SFF Up To 32GB RAM 1TB SSD Windows 10 Pro Wi-Fi

$172.78



Lenovo Micro Desktop Computer PC, Up to 16 GB RAM 1TB SSD, Windows 11/10 WiFi picture

Lenovo Micro Desktop Computer PC, Up to 16 GB RAM 1TB SSD, Windows 11/10 WiFi

$179.00



Discussions

No Discussions have been posted on this vulnerability.