vendor:
Tiny HTTPd
by:
Touhid M.Shaikh
7,5
CVSS
HIGH
Local File Traversal
22
CWE
Product Name: Tiny HTTPd
Affected Version From: 0.1.0
Affected Version To: 0.1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:tiny_httpd:tiny_httpd:0.1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Tiny HTTPd 0.1.0 Local File Traversal
Tiny HTTPd 0.1.0 is vulnerable to Local File Traversal vulnerability. An attacker can exploit this vulnerability to read sensitive files from the server. To exploit this vulnerability, an attacker can send a specially crafted HTTP request containing directory traversal characters (e.g. '../') to the vulnerable server. This will allow the attacker to read sensitive files from the server.
Mitigation:
Upgrade to the latest version of Tiny HTTPd or apply the patch provided by the vendor.