Vulnerabilities > CVE-2007-3407 - Unspecified vulnerability in Sergey Lyubka Simple Httpd 1.38
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | SHTTPD 1.38 Filename Parse Error Information Disclosure Vulnerability. CVE-2007-3407. Remote exploits for multiple platform |
id | EDB-ID:30229 |
last seen | 2016-02-03 |
modified | 2007-06-25 |
published | 2007-06-25 |
reporter | Shay Priel |
source | https://www.exploit-db.com/download/30229/ |
title | SHTTPD 1.38 Filename Parse Error Information Disclosure Vulnerability |
Nessus
NASL family | Web Servers |
NASL id | ASP_SOURCE_SPACE.NASL |
description | It appears possible to get the source code of the remote ASP scripts by appending a |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11071 |
published | 2002-08-14 |
reporter | This script is Copyright (C) 2002-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/11071 |
title | Multiple Web Server Encoded Space (%20) Request ASP Source Disclosure |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 24618 CVE(CAN) ID: CVE-2007-3407 SHTTPD是一款轻量级的简单易用的web服务器。 SHTTPD处理HTTP请求时存在漏洞,远程攻击者可能利用此漏洞获取脚本源码。 SHTTPD没有正确地处理HTTP请求,如果用户在所提交的URI后附加了“%20”字符的话,就可能导致泄露某些脚本的源码。 Sergey Lyubka SHTTPD 1.38 目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本: <a href="http://shttpd.sourceforge.net/" target="_blank">http://shttpd.sourceforge.net/</a> |
id | SSV:1940 |
last seen | 2017-11-19 |
modified | 2007-06-29 |
published | 2007-06-29 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-1940 |
title | SHTTPD文件名解析错误信息泄露漏洞 |
References
- http://osvdb.org/37732
- http://osvdb.org/37732
- http://secunia.com/advisories/25809
- http://secunia.com/advisories/25809
- http://securityreason.com/securityalert/2832
- http://securityreason.com/securityalert/2832
- http://www.securityfocus.com/archive/1/472190/100/0/threaded
- http://www.securityfocus.com/archive/1/472190/100/0/threaded
- http://www.securityfocus.com/bid/24618
- http://www.securityfocus.com/bid/24618
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35038
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35038