Advisories for Npm/Dasafio package

2018

Path Traversal

dasafio is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing ../ in the url.

2017

Directory Traversal

dasafio is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. File access is restricted to only .html files./n