vendor:
thttpd, mini_httpd
by:
Unknown
7.5
CVSS
HIGH
Command Injection
78
CWE
Product Name: thttpd, mini_httpd
Affected Version From: thttpd 2.25b, mini_httpd 1.19
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:acme:thttpd:2.25b, cpe:/a:acme:mini_httpd:1.19
Platforms Tested:
Unknown
Command Injection in Acme ‘thttpd’ and ‘mini_httpd’
The Acme 'thttpd' and 'mini_httpd' web servers are vulnerable to command injection due to insufficient input sanitization in logfiles. An attacker can exploit this vulnerability to execute arbitrary commands in a terminal.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the affected web servers when available. Additionally, ensure that user-supplied input is properly sanitized to prevent command injection attacks.