Описание
Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
Ссылки
- Third Party Advisory
- Release Notes
- Third Party Advisory
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия до 2.22 (включая)
cpe:2.3:a:acme:thttpd:*:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00713
Низкий
5 Medium
CVSS2
Дефекты
CWE-668
Связанные уязвимости
github
больше 3 лет назад
Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
EPSS
Процентиль: 72%
0.00713
Низкий
5 Medium
CVSS2
Дефекты
CWE-668