vendor:
Small HTTP server
by:
basher13 - basher13(at)linuxmail.org
7.5
CVSS
HIGH
Arbitrary Data Execution
78
CWE
Product Name: Small HTTP server
Affected Version From: Small HTTP server 3.05.28
Affected Version To: Small HTTP server 3.05.28
Patch Exists: Yes
Related CWE: N/A
CPE: a:srv.mf.inc.ru:small_http_server:3.05.28
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2000 SP4 (Win NT)
Unknown
sHTTP FTPServer Abritary Data Execution Exploit
This exploit allows an attacker to execute arbitrary data on a vulnerable sHTTP FTPServer. The exploit works by connecting to the server, sending user and pass credentials, and then backing up the target file and setting a homepage defacement. The exploit was tested on Windows 2000 SP4 (Win NT).
Mitigation:
Ensure that all software is up to date and patched with the latest security updates.