First published: Sat Apr 26 2003(Updated: )
Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/thttpd | ||
thttpd (Acme Labs) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1562 is considered a medium severity vulnerability due to its potential to expose sensitive files.
To fix CVE-2002-1562, you should upgrade to a patched version of thttpd that addresses this directory traversal vulnerability.
CVE-2002-1562 affects users of the thttpd web server, particularly those utilizing virtual hosting.
Attackers can exploit CVE-2002-1562 to access arbitrary files on the server by manipulating the Host: header.
CVE-2002-1562 is less of a risk for modern systems that have patched thttpd or do not use this web server.