Vulnerabilities > CVE-2001-1433 - Unspecified vulnerability in Cherokee Httpd
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN cherokee
nessus
Summary
Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Nessus
NASL family | Web Servers |
NASL id | CHEROKEE_REMOTE_CMD.NASL |
description | The remote host is running Cherokee - a fast and tiny web server. The remote version of this software is vulnerable to remote command execution due to a lack of web requests sanitization, especially shell metacharacters. Additionally, this version fails to drop root privileges after it binds to listen port. A remote attacker may submit a specially crafted web request to execute arbitrary command on the server with root privileges. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15622 |
published | 2004-11-04 |
reporter | This script is Copyright (C) 2004-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/15622 |
title | Cherokee Web Server Port Bind Privilege Drop Weakness |
code |
|