- EPSS 3.01%
- Published 02.02.2007 21:28:00
- Last modified 09.04.2025 00:30:58
thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.
CVE-2006-4248
- EPSS 0.05%
- Published 31.10.2006 19:07:00
- Last modified 09.04.2025 00:30:58
thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.
CVE-2006-1078
- EPSS 0.23%
- Published 09.03.2006 00:02:00
- Last modified 03.04.2025 01:03:51
Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is n...
CVE-2006-1079
- EPSS 0.19%
- Published 09.03.2006 00:02:00
- Last modified 03.04.2025 01:03:51
htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd i...
CVE-2005-3124
- EPSS 0.1%
- Published 06.11.2005 11:02:00
- Last modified 03.04.2025 01:03:51
syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.
- EPSS 8.49%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such a...
- EPSS 1.95%
- Published 12.05.2003 04:00:00
- Last modified 03.04.2025 01:03:51
Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.
CVE-2002-0733
- EPSS 9.59%
- Published 12.08.2002 04:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.
CVE-2000-0900
- EPSS 1.19%
- Published 19.12.2000 05:00:00
- Last modified 03.04.2025 01:03:51
Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.
- EPSS 3.66%
- Published 20.10.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.