PT-2014-6247 · Bozotic · Bozohttpd
Published
2014-07-24
·
Updated
2017-08-29
·
CVE-2014-5015
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
bozotic HTTP server (aka bozohttpd) versions before 20140708
Description
The issue allows remote attackers to bypass the HTTP authentication scheme and access restrictions. This is achieved by exploiting the path truncation when checking .htpasswd restrictions, enabling access to otherwise restricted areas via a long path.
Recommendations
For versions before 20140708, update to version 20140708 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bozohttpd