GeSHi vulnerable to Directory Traversal
High severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 14, 2025
Description
Published by the National Vulnerability Database
Jun 13, 2014
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Apr 14, 2025
Last updated
Apr 14, 2025
Multiple directory traversal vulnerabilities in the cssgen contrib module in GeSHi before 1.0.8.11 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) geshi-path or (2) geshi-lang-path parameter.
References