Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a %2e%2e string, a variation of the .. (dot dot) attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Thttpd | Acme_labs | 2.16 | 2.16 |
Thttpd | Acme_labs | 2.17 | 2.17 |
Thttpd | Acme_labs | 2.18 | 2.18 |
Thttpd | Acme_labs | 2.19 | 2.19 |