Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-16136 – In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permissio

In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permission to download logs can download any file on the server machine (accessible by the owner of the server process) via directory traversal ../ sequences in /Administration/Logs/ requests. The attacker is unable to enumerate files, however.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16136

Reference (s):

  • https://github.com/tgstation/tgstation-server
  • https://github.com/tgstation/tgstation-server/security/advisories/GHSA-r8pp-42wr-2gc4
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-4742 - Cross-site scripting (XSS) vulnerability in system/class_link.php in the

2021-current

CVE-2014-9837 - coders/pnm.c in ImageMagick 6.9.0-1 Beta and earlier allows remote attack

2021-current

CVE-2020-10446 - The way URIs are handled in admin/header.php in Chadha PHPKB Standard Mul