Skip to content
Noroxi

http-file-server project records

2 published records for vendor http-file-server project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 19

Bar: total · dark part: CISA KEV.

All records

2 records
  • CVE-2019-5447
    21Monitor

    A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.

    MediumCVSS 5.3No exploitEPSS 2%

    http-file-server project · http-file-serverJul 15, 2019

  • CVE-2019-5458
    21Monitor

    Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to exec

    MediumCVSS 5.4No exploitEPSS 1%

    http-file-server project · http-file-serverJul 30, 2019