Directory traversal vulnerability in the HTTP file-serving module (modhttpfiles) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-1231.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "23"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
}
]