Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote malicious users to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:").
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
acme labs thttpd 2.0.7_beta_0.4 |