CVE-2000-0900: High severity Acme Labs thttpd vulnerability
Published Dec 19, 2000
·Updated
Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.
Affected Software
4 affected components
Acme Labs thttpd=2.19
Acme Labs thttpd=2.17
Acme Labs thttpd=2.18
Acme Labs thttpd=2.16
Event History
Dec 19, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0900?
CVE-2000-0900 has a severity rating of medium due to its potential for unauthorized file access.
2
How do I fix CVE-2000-0900?
To fix CVE-2000-0900, upgrade to thttpd version 2.20 or later where this vulnerability is resolved.
3
What is the impact of CVE-2000-0900?
CVE-2000-0900 allows remote attackers to read arbitrary files on the server, leading to potential data exposure.
4
Which versions of thttpd are affected by CVE-2000-0900?
CVE-2000-0900 affects thttpd versions 2.16 through 2.19.
5
Can CVE-2000-0900 be exploited remotely?
Yes, CVE-2000-0900 can be exploited remotely by sending specially crafted requests to the vulnerable server.