CVE-2016-1671

Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers to conduct directory traversal attacks via a file: URL, related to net/base/escape.cc and net/base/filename_util.cc.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2016-05-14 21:59

Updated : 2023-11-07 02:30


NVD link : CVE-2016-1671

Mitre link : CVE-2016-1671

CVE.ORG link : CVE-2016-1671


JSON object : View

Products Affected

google

  • android
  • chrome
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')