vendor:
thttpd
by:
5
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: thttpd
Affected Version From: 2.07 beta 0.4
Affected Version To: 2.07 beta 0.4
Patch Exists: NO
Related CWE:
CPE: thttpd
Platforms Tested: Windows
Directory Traversal Vulnerability in thttpd
The thttpd web server is susceptible to a directory traversal vulnerability due to insufficient sanitization of user-supplied data. This vulnerability only affects the Windows port of the application and allows an attacker to retrieve arbitrary files from the affected host computer.
Mitigation:
Upgrade to a version of thttpd that has patched this vulnerability. Additionally, ensure proper input validation and sanitization to prevent directory traversal attacks.