5

CVE-2014-5015

bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.

Data is provided by the National Vulnerability Database (NVD)
EternaBozohttpd Version <= 20140201
EternaBozohttpd Version19990519
EternaBozohttpd Version20000421
EternaBozohttpd Version20000426
EternaBozohttpd Version20000427
EternaBozohttpd Version20000815
EternaBozohttpd Version20000825
EternaBozohttpd Version20010610
EternaBozohttpd Version20010812
EternaBozohttpd Version20010922
EternaBozohttpd Version20020710
EternaBozohttpd Version20020730
EternaBozohttpd Version20020803
EternaBozohttpd Version20020804
EternaBozohttpd Version20020823
EternaBozohttpd Version20020913
EternaBozohttpd Version20021106
EternaBozohttpd Version20030313
EternaBozohttpd Version20030409
EternaBozohttpd Version20030626
EternaBozohttpd Version20031005
EternaBozohttpd Version20040218
EternaBozohttpd Version20040808
EternaBozohttpd Version20050410
EternaBozohttpd Version20060517
EternaBozohttpd Version20060710
EternaBozohttpd Version20080303
EternaBozohttpd Version20090417
EternaBozohttpd Version20090522
EternaBozohttpd Version20100509
EternaBozohttpd Version20100512
EternaBozohttpd Version20100617
EternaBozohttpd Version20100621
EternaBozohttpd Version20100920
EternaBozohttpd Version20111118
EternaBozohttpd Version20140102
NetbsdNetbsd Version5.1
NetbsdNetbsd Version5.2
NetbsdNetbsd Version6.0
NetbsdNetbsd Version6.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.57% 0.66
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N