PT-2014-6247 · Bozotic · Bozohttpd

Published

2014-07-24

·

Updated

2017-08-29

·

CVE-2014-5015

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions bozotic HTTP server (aka bozohttpd) versions before 20140708
Description The issue allows remote attackers to bypass the HTTP authentication scheme and access restrictions. This is achieved by exploiting the path truncation when checking .htpasswd restrictions, enabling access to otherwise restricted areas via a long path.
Recommendations For versions before 20140708, update to version 20140708 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-5015
DLA-490-1

Affected Products

Bozohttpd