|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
This Entry needs help! It is only 35% Complete. Click the edit link above to add more information.
Contributing is fast and easy, and benefits the entire security community.
|
|
Description |
(Description Provided by CVE) : Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI programs or scripts via a URI with an appended (1) '+' character, (2) '.' character, (3) %2e sequence (hex-encoded dot), or (4) hex-encoded character greater than 0x7f. NOTE: the %20 vector is already covered by CVE-2007-3407.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality
Solution:
No Solution
Disclosure:
Uncoordinated Disclosure
OSVDB:
Web Related
|
|
Products |
Unknown or Incomplete
|
|
|
|
Credit |
- Luigi Auriemma - aluigi
altervista.org - http://aluigi.altervista.org
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|