Junglewise Threat Intelligence

CVE-2017-16150: wangguojing123 directory traversal

CVE-2017-16150 · Severity: info · Published 2020-09-01

Vendors: npm.

Executive brief

wangguojing123 is a Node.js package that fails to properly validate file paths, allowing attackers to read arbitrary files on the server by using path traversal sequences (e.g., ../ in URLs). An attacker can exploit this to access sensitive files like /etc/passwd and other private data outside the intended application directory without authentication.

Technical details

The vulnerability is a path traversal (CWE-22) in wangguojing123 that occurs because the package resolves relative file paths without proper validation. An attacker can craft HTTP requests using directory traversal sequences (../) to escape the intended root directory and access arbitrary files on the system. The attack is network-accessible and requires no authentication. An exploit allows disclosure of sensitive files, including system configuration and private application data. No patch has been released; the vendor recommends restricting use to local development only.

Affected products

  • wangguojing123 wangguojing123 all versions

Timeline

  • 2020-09-01: disclosed
  • 2017: other: CVE-2017-16150 assigned

References