CVE-2014-6394
â ī¸ highSummary
visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.
CVSS Score
7.5
High
EPSS Score
4.8
Exploit Probability
Published Date
2014-10-08
First Seen: 2026-01-05
đ Relative Risk Intelligence
This CVE is Moderate Risk - more severe than 69.4% of all 317,883 vulnerabilities in our database.
#97,299
Above average severity
Severity Percentile
Last Modified
2025-04-12
Source
NVD đ
CWE IDs (Weakness Types)