CVE-2002-1562: Medium severity Acme Labs thttpd vulnerability
Published Apr 26, 2003
·Updated
Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.
Affected Software
2 affected components
debian/thttpd
Acme Labs thttpd
Event History
Apr 26, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1562?
CVE-2002-1562 is considered a medium severity vulnerability due to its potential to expose sensitive files.
2
How do I fix CVE-2002-1562?
To fix CVE-2002-1562, you should upgrade to a patched version of thttpd that addresses this directory traversal vulnerability.
3
Who is affected by CVE-2002-1562?
CVE-2002-1562 affects users of the thttpd web server, particularly those utilizing virtual hosting.
4
What can attackers do with CVE-2002-1562?
Attackers can exploit CVE-2002-1562 to access arbitrary files on the server by manipulating the Host: header.
5
Is CVE-2002-1562 still a risk for modern systems?
CVE-2002-1562 is less of a risk for modern systems that have patched thttpd or do not use this web server.