Vulnerabilities > CVE-1999-1456 - Unspecified vulnerability in Thttpd Http Server

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
thttpd
nessus

Summary

thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.

Vulnerable Configurations

Part Description Count
Application
Thttpd
1

Nessus

NASL familyWeb Servers
NASL idTHTTPD_BUG.NASL
descriptionThe remote HTTP server allows an attacker to read arbitrary files on the remote host with the privileges of the web server, simply by adding a slash in front of its name. For instance,
last seen2020-06-01
modified2020-06-02
plugin id10286
published1999-06-22
reporterThis script is Copyright (C) 1999-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/10286
titlethttpd Double Slash Request Arbitrary File Access