ID:11711 - Exploit for Path traversal in Mongoose - CVE-2009-1354
Published: June 23, 2025
Mongoose
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in Mongoose 2.4. A remote authenticated attacker can send a specially crafted HTTP request and remote attackers to read arbitrary files via a . (dot dot) in the URI.