NONE · 0

CVE-2010-10012

A path traversal vulnerability exists in httpdasm version 0.92, a lightweight Windows HTTP server, that allows unauthenticated attackers to read arbitrary files on the host system. By sending a specia...

Vulnerability Description

A path traversal vulnerability exists in httpdasm version 0.92, a lightweight Windows HTTP server, that allows unauthenticated attackers to read arbitrary files on the host system. By sending a specially crafted GET request containing a sequence of URL-encoded backslashes and directory traversal patterns, an attacker can escape the web root and access sensitive files outside of the intended directory.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-10012?

CVE-2010-10012 is a documented vulnerability. A path traversal vulnerability exists in httpdasm version 0.92, a lightweight Windows HTTP server, that allows unauthenticated attackers to read arbitrary files on the host system. By sending a specia...

How severe is CVE-2010-10012?

CVSS scoring is not yet available for CVE-2010-10012. Check NVD for updates.

Is there a patch for CVE-2010-10012?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.