### [CVE-2017-14849](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14849) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/Goby - https://github.com/ARPSyndicate/cvemon - https://github.com/ARPSyndicate/kenzer-templates - https://github.com/CLincat/vulcat - https://github.com/Elsfa7-110/kenzer-templates - https://github.com/Fa1c0n35/Web-CTF-Cheatshee - https://github.com/H4cking2theGate/TraversalHunter - https://github.com/HimmelAward/Goby_POC - https://github.com/JoyChou93/sks - https://github.com/SexyBeast233/SecBooks - https://github.com/Threekiii/Awesome-POC - https://github.com/Threekiii/Vulhub-Reproduce - https://github.com/Z0fhack/Goby_POC - https://github.com/Zxser/Web-CTF-Cheatsheet - https://github.com/anthager/TDA602-DIT101-NodeExploit - https://github.com/bakery312/Vulhub-Reproduce - https://github.com/bigblackhat/oFx - https://github.com/d4n-sec/d4n-sec.github.io - https://github.com/duckstroms/Web-CTF-Cheatsheet - https://github.com/heane404/CVE_scan - https://github.com/hxysaury/saury-vulnhub - https://github.com/ilmila/J2EEScan - https://github.com/junwonheo/junwonheo.github.io - https://github.com/mengdaya/Web-CTF-Cheatsheet - https://github.com/merlinepedra/nuclei-templates - https://github.com/merlinepedra25/nuclei-templates - https://github.com/openx-org/BLEN - https://github.com/q99266/saury-vulnhub - https://github.com/ronoski/j2ee-rscan - https://github.com/snyk-labs/container-breaking-in-goof - https://github.com/sobinge/nuclei-templates - https://github.com/superfish9/pt - https://github.com/w181496/Web-CTF-Cheatsheet