CVE-2017-16150: Directory Traversal in wangguojing123
5
CVSS Score
Basic Information
CVE ID
GHSA ID
EPSS Score
0.67352%
CWE
Published
9/1/2020
Updated
9/15/2023
KEV Status
No
Technology
JavaScript
Technical Details
CVSS Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
---|---|---|---|
wangguojing123 | npm | >= 0.0.0 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The provided vulnerability information and references do not include concrete source code, commit diffs, or specific function names from the wangguojing123
package. While the vulnerability is clearly described (improper path resolution leading to directory traversal), the lack of accessible code or implementation details makes it impossible to identify specific functions, their file paths, or their names with high confidence. The vulnerability likely resides in the file-serving logic that processes user-supplied URLs without proper sanitization, but without explicit code examples, this remains an inference rather than a confirmed fact.