Vulnerabilities
Vulnerable Software
Acme:  >> Thttpd  >> 2.22  Security Vulnerabilities
The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution.
CVSS Score
9.8
EPSS Score
0.008
Published
2018-02-06
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.
CVSS Score
9.8
EPSS Score
0.292
Published
2003-11-03
Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
CVSS Score
5.0
EPSS Score
0.004
Published
2001-11-13


Contact Us

Shodan ® - All rights reserved