Vulnerabilities > CVE-2003-1137 - Remote Information Disclosure vulnerability in Charles Steinkuehler Sh-Httpd 0.3/0.4

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
charles-steinkuehler
exploit available

Summary

Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.

Vulnerable Configurations

Part Description Count
Application
Charles_Steinkuehler
2

Exploit-Db

descriptionSH-HTTPD 0.3/0.4 Character Filtering Remote Information Disclosure Vulnerability. CVE-2003-1137. Remote exploit for linux platform
idEDB-ID:23295
last seen2016-02-02
modified2003-10-27
published2003-10-27
reporterdong-h0un U
sourcehttps://www.exploit-db.com/download/23295/
titleSH-HTTPD 0.3/0.4 Character Filtering Remote Information Disclosure Vulnerability