VYPR

HTTP File Server

by HTTP File Server Project

CVEs (3)

  • CVE-2021-40668HigJun 9, 2022
    risk 0.53cvss 8.1epss 0.01

    The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability that permits arbitrary directory listing, file read, and file write.

  • CVE-2019-5458MedJul 30, 2019
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.

  • CVE-2019-5447MedJul 15, 2019
    risk 0.35cvss 5.3epss 0.01

    A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.