VYPR
High severity7.5NVD Advisory· Published Jun 7, 2018· Updated Jun 17, 2026

CVE-2017-16198

CVE-2017-16198

Description

ritp is a static web server. ritp is vulnerable to a directory traversal issue whereby an attacker can gain access to the file system by placing ../ in the URL. Access is restricted to files with a file extension, so files such as /etc/passwd are not accessible.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ritpnpm
<= 1.0.5—

Affected products

5
  • Ritp Project/Ritp4 versions
    cpe:2.3:a:ritp_project:ritp:1.0.2:*:*:*:*:node.js:*:*+ 3 more
    • cpe:2.3:a:ritp_project:ritp:1.0.2:*:*:*:*:node.js:*:*
    • cpe:2.3:a:ritp_project:ritp:1.0.3:*:*:*:*:node.js:*:*
    • cpe:2.3:a:ritp_project:ritp:1.0.4:*:*:*:*:node.js:*:*
    • cpe:2.3:a:ritp_project:ritp:1.0.5:*:*:*:*:node.js:*:*
  • ghsa-coords
    Range: <= 1.0.5

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.