CVE-2015-5688
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 9.4%
exploitation probability
9.4%top 5% of all CVEs
observed exploitation
nono source reports it
Directory traversal vulnerability in lib/app/index.js in Geddy before 13.0.8 for Node.js allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the PATH_INFO to the default URI.
Affected products
n/a · n/a