4.3
CVSSv2

CVE-2015-1164

Published: 21/01/2015 Updated: 08/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Open redirect vulnerability in the serve-static plugin prior to 1.7.2 for Node.js, when mounted at the root, allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the PATH_INFO to the default URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

serve-static project serve-static

Vendor Advisories

Debian Bug report logs - #775843 node-serve-static: CVE-2015-1164 Package: node-serve-static; Maintainer for node-serve-static is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Source for node-serve-static is src:node-serve-static (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@in ...