CVE-2004-2628 – Acme thttpd 2.0.7 - Directory Traversal
https://notcve.org/view.php?id=CVE-2004-2628
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:"). • https://www.exploit-db.com/exploits/24350 http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0097.html http://marc.info/?l=bugtraq&m=109164010629836&w=2 http://securitytracker.com/alerts/2004/Aug/1010850.html http://www.acme.com/software/thttpd/#releasenotes http://www.osvdb.org/displayvuln.php?osvdb_id=8372 http://www.securityfocus.com/bid/10862 https://exchange.xforce.ibmcloud.com/vulnerabilities/16882 •
CVE-2002-1562
https://notcve.org/view.php?id=CVE-2002-1562
Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header. Vulnerabilidad de atravesamiento de directorios en thttpd, cuando se usan servidores virtuales, permite a atacantes remotos leer ficheros mediante secuencias .. (punto punto) en la cabecera Host: • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000777 http://marc.info/?l=thttpd&m=103609565110472&w=2 http://news.php.net/article.php?group=php.cvs&article=15698 https://www.debian.org/security/2003/dsa-396 •
CVE-2002-0733 – ACME Labs thttpd 2.20 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2002-0733
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message. Vulnerabilidad de secuencia de comandos en sitios cruzados en thttpd 2.20 y anteriores permite a atacantes remotos la ejecución arbitraria de rutinas mediante una URL a una página inexistente, lo cual provoca que thttpd inserte la rutina en un mensaje de error 404. • https://www.exploit-db.com/exploits/21422 http://archives.neohapsis.com/archives/vuln-dev/2002-q2/0155.html http://www.acme.com/software/thttpd/#releasenotes http://www.ifrance.com/kitetoua/tuto/5holes1.txt http://www.iss.net/security_center/static/9029.php http://www.osvdb.org/5125 http://www.securityfocus.com/bid/4601 •
CVE-2000-0900
https://notcve.org/view.php?id=CVE-2000-0900
Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack. • ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:73.thttpd.asc http://archives.neohapsis.com/archives/bugtraq/2000-10/0025.html http://www.securityfocus.com/bid/1737 https://exchange.xforce.ibmcloud.com/vulnerabilities/5313 •
CVE-2000-0359
https://notcve.org/view.php?id=CVE-2000-0359
Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header. • http://archives.neohapsis.com/archives/bugtraq/1626.html http://www.novell.com/linux/security/advisories/suse_security_announce_30.html http://www.securityfocus.com/bid/1248 •