| Vulnerability Name: | CVE-2001-0892 (CCN-7541) | ||||||||
| Assigned: | 2001-11-13 | ||||||||
| Published: | 2001-11-13 | ||||||||
| Updated: | 2021-09-13 | ||||||||
| Summary: | Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
| Vulnerability Type: | CWE-668 | ||||||||
| Vulnerability Consequences: | File Manipulation | ||||||||
| References: | Source: MITRE Type: CNA CVE-2001-0892 Source: MITRE Type: CNA CVE-2001-0893 Source: BUGTRAQ Type: Third Party Advisory 20011113 Cgisecurity.com Advisory #6: thttpd and mini_http Permission bypass vuln Source: CCN Type: mini_httpd Changelog mini_httpd - small HTTP server Source: CCN Type: Thttpd Changelog thttpd - tiny/turbo/throttling HTTP server Source: CONFIRM Type: Release Notes http://www.acme.com/software/thttpd/ Source: CCN Type: Cgi Security Advisory #6 Thttpd and Mini_Httpd Webserver Permission Bypass Source: CCN Type: OSVDB ID: 13984 Acme mini_httpd Trailing / Request Privilege File Access Source: CCN Type: OSVDB ID: 7360 thttpd URL Trailing Slash Arbitrary File Access Source: XF Type: UNKNOWN httpd-bypass-permissions(7541) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||