Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-5015

Опубликовано: 24 июл. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [20111118-1+deb7u1build0.14.04.1]]
lucid

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
trusty

released

20111118-1+deb7u1build0.14.04.1
trusty/esm

DNE

trusty was released [20111118-1+deb7u1build0.14.04.1]
upstream

released

20140708
utopic

ignored

end of life
vivid

DNE

Показывать по

EPSS

Процентиль: 68%
0.00573
Низкий

5 Medium

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.

debian
больше 11 лет назад

bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD ...

github
больше 3 лет назад

bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.

EPSS

Процентиль: 68%
0.00573
Низкий

5 Medium

CVSS2