[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

251782

 
 

909

 
 

196543

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-2320Date: (C)2010-08-02   (M)2023-12-22


bozotic HTTP server (aka bozohttpd) before 20100621 allows remote attackers to list the contents of home directories, and determine the existence of user accounts, via multiple requests for URIs beginning with /~ sequences.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECUNIA-40737
bozohttp-publichtml-info-disclosure(60812)
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590298
http://security-tracker.debian.org/tracker/CVE-2010-2320
http://www.eterna.com.au/bozohttpd/CHANGES
https://bugs.launchpad.net/ubuntu/+source/bozohttpd/+bug/582473

CPE    30
cpe:/a:eterna:bozohttpd:20010610
cpe:/a:eterna:bozohttpd:20040808
cpe:/a:eterna:bozohttpd:20060517
cpe:/a:eterna:bozohttpd:20010812
...
CWE    1
CWE-264

© SecPod Technologies