Vulnerability Description
Directory traversal vulnerability in Doug Neal's HTTPD Daemon (DNHTTPD) before 0.4.1 allows remote attackers to view arbitrary files via a .. (dot dot) attack using the dot hex code '%2E'.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Doug Neal | Dnhttpd | 0.4.1 |
References
- http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0002.htmlVendor Advisory
- http://dnhttpd.sourceforge.net/changelog.html
- http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0002.htmlVendor Advisory
- http://dnhttpd.sourceforge.net/changelog.html
FAQ
What is CVE-2001-1266?
CVE-2001-1266 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Directory traversal vulnerability in Doug Neal's HTTPD Daemon (DNHTTPD) before 0.4.1 allows remote attackers to view arbitrary files via a .. (dot dot) attack using the dot hex code '%2E'.
How severe is CVE-2001-1266?
CVE-2001-1266 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1266?
Check the references section above for vendor advisories and patch information. Affected products include: Doug Neal Dnhttpd.