7.5

CVE-2000-0900

Exploit

Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.

Data is provided by the National Vulnerability Database (NVD)
Acme LabsThttpd Version2.16
Acme LabsThttpd Version2.17
Acme LabsThttpd Version2.18
Acme LabsThttpd Version2.19
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.19% 0.769
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P