CVE-2004-1444
Roundup Directory traversal vulnerability
EPSS 16.5%
Description
Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via `..` (dot dot) sequences in an `@@` command in an HTTP GET request.
How to fix CVE-2004-1444
To remediate CVE-2004-1444, upgrade the affected package to a fixed version below.
- PyPI/roundup—upgrade to 0.7.3 or later
Is CVE-2004-1444 being exploited?
Moderate — EPSS is 16.5%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.7.3