#VU111841 Path traversal in Mongoose - CVE-2009-1354
Published: October 10, 2018 / Updated: June 23, 2025
Mongoose
Cesanta Software Ltd.
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in Mongoose 2.4. A remote authenticated attacker can send a specially crafted HTTP request and remote attackers to read arbitrary files via a . (dot dot) in the URI.