6.4
CVSSv2

CVE-2007-6405

Published: 17/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Sergey Lyubka Simple HTTPD (shttpd) 1.38 and previous versions on Windows allows remote malicious users to download arbitrary CGI programs or scripts via a URI with an appended (1) '+' character, (2) '.' character, (3) %2e sequence (hex-encoded dot), or (4) hex-encoded character greater than 0x7f. NOTE: the %20 vector is already covered by CVE-2007-3407.

Vulnerable Product Search on Vulmon Subscribe to Product

shttpd shttpd 1.34

shttpd shttpd 1.35

shttpd shttpd 1.38

Exploits

####################################################################### Luigi Auriemma Application: Simple HTTPD shttpdsourceforgenet Versions: <= 138 Platforms: Windows, *nix, QNX, RTEMS only Windows seems vulnerable Bugs: A] directory traversal B ...