Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-5269
Description:Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to bypass the whitelist of generated files and obtain sensitive information via a crafted path, related to Plack::Middleware::Static.
Test IDs: 1.3.6.1.4.1.25623.1.0.868139   1.3.6.1.4.1.25623.1.1.1.2.2014.61   1.3.6.1.4.1.25623.1.1.10.2014.0486   1.3.6.1.4.1.25623.1.0.868140  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-5269
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137115.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137099.html
http://seclists.org/oss-sec/2014/q3/384
http://www.osvdb.org/109928




© 1998-2025 E-Soft Inc. All rights reserved.