PT-2001-2047 · Acme · Acme Thttpd Secure Webserver

Published

2001-11-13

·

Updated

2021-09-13

·

CVE-2001-0892

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Acme Thttpd Secure Webserver versions prior to 2.22
Description The issue allows remote attackers to view sensitive files under the document root, such as .htpasswd, via a GET request with a trailing /. This is possible when the chroot option is enabled.
Recommendations For versions prior to 2.22, consider disabling the chroot option as a temporary workaround until a patch is available. Restrict access to sensitive files under the document root to minimize the risk of exploitation.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2001-0892

Affected Products

Acme Thttpd Secure Webserver