Vulnerabilities > CVE-2004-2628 - Unspecified vulnerability in Acme Labs Thttpd 2.0.7Beta0.4
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:").
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Acme thttpd 2.0.7 Directory Traversal Vulnerability. CVE-2004-2628. Remote exploit for windows platform |
id | EDB-ID:24350 |
last seen | 2016-02-02 |
modified | 2004-08-04 |
published | 2004-08-04 |
reporter | CoolICE |
source | https://www.exploit-db.com/download/24350/ |
title | acme thttpd 2.0.7 - Directory Traversal Vulnerability |
Nessus
NASL family | Web Servers |
NASL id | THTTPD_DIRECTORY_TRAVERSAL.NASL |
description | The remote web server fails to limit requests to items within the document directory. An attacker may exploit this flaw to read arbitrary files on the remote system with the privileges of the http process. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14229 |
published | 2004-08-09 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/14229 |
title | thttpd 2.0.7 Directory Traversal (Windows) |
code |
|
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0097.html
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0097.html
- http://marc.info/?l=bugtraq&m=109164010629836&w=2
- http://marc.info/?l=bugtraq&m=109164010629836&w=2
- http://securitytracker.com/alerts/2004/Aug/1010850.html
- http://securitytracker.com/alerts/2004/Aug/1010850.html
- http://www.acme.com/software/thttpd/#releasenotes
- http://www.acme.com/software/thttpd/#releasenotes
- http://www.osvdb.org/displayvuln.php?osvdb_id=8372
- http://www.osvdb.org/displayvuln.php?osvdb_id=8372
- http://www.securityfocus.com/bid/10862
- http://www.securityfocus.com/bid/10862
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16882
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16882