bozohttpd Security Bypass Vulnerability
BID:42021
Info
bozohttpd Security Bypass Vulnerability
| Bugtraq ID: | 42021 |
| Class: | Design Error |
| CVE: |
CVE-2010-2195 CVE-2010-2320 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2010 12:00AM |
| Updated: | Jul 28 2010 12:00AM |
| Credit: | Claudio Clemens |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
bozohttpd Security Bypass Vulnerability
bozohttpd is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and gain access to restricted content. This can lead to other attacks.
bozohttpd 20090522 and 20100509 are vulnerable; other versions may also be affected.
bozohttpd is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and gain access to restricted content. This can lead to other attacks.
bozohttpd 20090522 and 20100509 are vulnerable; other versions may also be affected.
Exploit / POC
bozohttpd Security Bypass Vulnerability
Attackers can exploit this issue with readily available tools.
Attackers can exploit this issue with readily available tools.
Solution / Fix
bozohttpd Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
bozohttpd Security Bypass Vulnerability
References:
References:
- bozohttpd show index of /homt/user if there is no public_html there (Canonical Ltd.)
- bozohttpd Homepage (bozohttpd)