5
CVSSv2

CVE-2007-5685

Published: 28/10/2007 Updated: 15/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The safe_path function in shttp prior to 0.0.5 allows remote malicious users to conduct directory traversal attacks and read files via a combination of ".." and sub-directory specifiers that resolve to a pathname that is at or below the same level as the web document root, but in a different part of the directory tree.

Vulnerable Product Search on Vulmon Subscribe to Product

serverkit shttp

Exploits

source: wwwsecurityfocuscom/bid/26212/info Shttp is prone to a remote directory-traversal vulnerability A remote attacker can exploit this issue by using directory-traversal sequences to retrieve arbitrary files on a victim user's computer Versions prior to Shttp005 are vulnerable to this issue HEAD ///etc/passwd HTTP/10 HTT ...