Loading
Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote attackers to read arbitrary files via a crafted URL.
Cite this page
CVE-2015-5638. CVEDatabase.com. Retrieved 3 May 2026. https://cvedatabase.com/cve/CVE-2015-5638
Use CWE-22, Dena vendor hub and H20 product page to widen CVE-2015-5638 into its surrounding weakness, vendor, and product context.