SHTTPD Filename Parse Error Information Disclosure Vulnerability
BID:24618
Info
SHTTPD Filename Parse Error Information Disclosure Vulnerability
| Bugtraq ID: | 24618 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3407 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Shay Priel is credited with the discovery of this vulnerability. |
| Vulnerable: |
SHTTPD SHTTPD 1.38 |
| Not Vulnerable: | |
Discussion
SHTTPD Filename Parse Error Information Disclosure Vulnerability
SHTTPD is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to access sensitive information that may lead to further attacks.
This issue affects SHTTPD 1.38; other versions may also be affected.
SHTTPD is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to access sensitive information that may lead to further attacks.
This issue affects SHTTPD 1.38; other versions may also be affected.
Exploit / POC
SHTTPD Filename Parse Error Information Disclosure Vulnerability
An attacker can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/test.php%20
An attacker can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/test.php%20
Solution / Fix
SHTTPD Filename Parse Error Information Disclosure Vulnerability
Solution:
Currently we are not aware of any solutions for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any solutions for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SHTTPD Filename Parse Error Information Disclosure Vulnerability
References:
References:
- SHTTPD (Simple HTTPD) Homepage (Sergey Lyubka )
- SHTTPD V1.38 server source code disclosure (Shay priel)