4 results (0.007 seconds)

CVSS: 9.8EPSS: 1%CPEs: 2EXPL: 0

06 Feb 2018 — The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution. La implementación htpasswd de mini_httpd, en versiones anteriores a la v1.28 y de thttpd, en versiones anteriores a la v2.28, se ha visto afectada por un desbordamiento de búfer que podría ser explotado de forma remota para ejecutar código. • http://acme.com/updates/archive/199.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.5EPSS: 2%CPEs: 1EXPL: 1

02 Feb 2007 — thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files. thttpd anterior a 2.25b-r6 en Gentoo Linux es iniciado desde el directorio raíz del sistema (/) por el paquete de distribución base 1.12.6 de Gentoo, lo cual permite a atacantes remotos leer archivos de su elección. m-privacy TightGate-Pro suffers from code execution, insecure permissions, deletion mitigation, and outdated server... • https://packetstorm.news/files/id/175949 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

13 Nov 2001 — Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /. • http://marc.info/?l=bugtraq&m=100568999726036&w=2 • CWE-668: Exposure of Resource to Wrong Sphere •

CVSS: 10.0EPSS: 3%CPEs: 7EXPL: 0

12 Jul 2000 — Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header. • http://archives.neohapsis.com/archives/bugtraq/1626.html •