Filtered by vendor Cherrypy
                         Subscriptions
                    
                    
                
                        Filtered by product Cherrypy
                         Subscriptions
                    
                    
                
                    Total
                    2 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2008-0252 | 1 Cherrypy | 1 Cherrypy | 2025-04-09 | N/A | 
| Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py in CherryPy 2.1, and (3) filter/sessionfilter.py in CherryPy 2.x allows remote attackers to create or delete arbitrary files, and possibly read and write portions of arbitrary files, via a crafted session id in a cookie. | ||||
| CVE-2006-0847 | 1 Cherrypy | 1 Cherrypy | 2025-04-03 | N/A | 
| Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via ".." sequences in unspecified vectors. | ||||
                            
                                
                                
                                    Page 1 of 1.