Acme Labs

Thttpd

10 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.01%
  • Published 02.02.2007 21:28:00
  • Last modified 09.04.2025 00:30:58

thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.

  • EPSS 0.05%
  • Published 31.10.2006 19:07:00
  • Last modified 09.04.2025 00:30:58

thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.

  • EPSS 0.23%
  • Published 09.03.2006 00:02:00
  • Last modified 03.04.2025 01:03:51

Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is n...

  • EPSS 0.19%
  • Published 09.03.2006 00:02:00
  • Last modified 03.04.2025 01:03:51

htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd i...

  • EPSS 0.1%
  • Published 06.11.2005 11:02:00
  • Last modified 03.04.2025 01:03:51

syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.

Exploit
  • EPSS 8.49%
  • Published 31.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such a...

  • EPSS 1.95%
  • Published 12.05.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.

Exploit
  • EPSS 9.59%
  • Published 12.08.2002 04:00:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.

Exploit
  • EPSS 1.19%
  • Published 19.12.2000 05:00:00
  • Last modified 03.04.2025 01:03:51

Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.

  • EPSS 3.66%
  • Published 20.10.2000 04:00:00
  • Last modified 03.04.2025 01:03:51

Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.