CVE-2007-3407: Medium severity Sergey Lyubka Simple HTTPD vulnerability
Published Jun 26, 2007
·Updated
Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20).
Affected Software
1 affected component
Sergey Lyubka Simple HTTPD=1.38
Remediation
Patch Available
Event History
Jun 26, 2007
CVE Published
06:30 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3407?
CVE-2007-3407 is classified as a medium severity vulnerability that can lead to information disclosure.
2
How do I fix CVE-2007-3407?
To fix CVE-2007-3407, upgrade to a later version of Sergey Lyubka Simple HTTPD that addresses the trailing encoded space vulnerability.
3
What type of information can be disclosed by CVE-2007-3407?
CVE-2007-3407 allows remote attackers to access sensitive information such as script source code.
4
Who is affected by CVE-2007-3407?
CVE-2007-3407 affects users of Sergey Lyubka Simple HTTPD version 1.38.
5
Is CVE-2007-3407 a remote vulnerability?
Yes, CVE-2007-3407 is a remote vulnerability that can be exploited by attackers without physical access.