VYPR
Vendor

HTTP File Server Project

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2021-40668HigJun 9, 2022
    risk 0.53cvss 8.1epss 0.01

    The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability that permits arbitrary directory listing, file read, and file write.

  • CVE-2019-5458MedJul 30, 2019
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.

  • CVE-2019-5447MedJul 15, 2019
    risk 0.35cvss 5.3epss 0.01

    A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.