5
CVSSv2

CVE-2003-1137

Published: 27/10/2003 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote malicious users to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.

Vulnerable Product Search on Vulmon Subscribe to Product

charles steinkuehler sh-httpd 0.4

charles steinkuehler sh-httpd 0.3

Exploits

source: wwwsecurityfocuscom/bid/8897/info A problem has been identified in the handling of some characters by sh-httpd Because of this, an attacker may be able to gain unauthorized access to information GET * GET ///sh-httpd/p* GET ///etc/s* GET //root/b* ...