Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a %2e%2e string, a variation of the .. (dot dot) attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Thttpd | Acme_labs | 2.16 (including) | 2.16 (including) |
Thttpd | Acme_labs | 2.17 (including) | 2.17 (including) |
Thttpd | Acme_labs | 2.18 (including) | 2.18 (including) |
Thttpd | Acme_labs | 2.19 (including) | 2.19 (including) |