VulnerabilityModified
CVE-2001-0892
Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
MEDIUM 5.0EPSS 1.86%
Does this matter?
Lower severity and a low EPSS score (1.86%). Track it; it rarely justifies an emergency change on its own.
Description
Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.86% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-668
- Affected
- acme/thttpd
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=100568999726036&w=2Third Party Advisory
- http://www.acme.com/software/thttpd/Release Notes
- http://marc.info/?l=bugtraq&m=100568999726036&w=2Third Party Advisory
- http://www.acme.com/software/thttpd/Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.