Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2004-2628

EPSS 8.49% · P92
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2004-2628

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:").
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
thttpd远程目录遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
thttpd是ACME实验室的一款轻量级的HTTP服务器,它支持基于URL的文件流量限制,以及支持多种平台,如FreeBSD、SunOS、Solaris、BSD等。 thttpd不正确处理用户提交的URI请求,远程攻击者可以利用这个漏洞以WEB权限在系统上查看任意文件内容。 thttpd对部分编码缺少正确处理,攻击者可以提交类似'%5c..'的字符绕过WEB ROOT限制,以WEB进程权限在系统上查看任意文件内容。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2004-2628

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2004-2628

Please Login to view more intelligence information

Same Patch Batch · n/a · 2005-12-04 · 55 CVEs total

CVE-2004-2640LinuxStat远程目录遍历漏洞
CVE-2005-3991PHPMyChat 多个跨站脚本攻击漏洞
CVE-2005-3985Astaro Security Linux ISAKMP IKE Traffic 拒绝服务漏洞
CVE-2005-3988Lore Article.PHP SQL注入漏洞
CVE-2005-3987Tradesoft CMS多个SQL注入漏洞
CVE-2005-3986Instant Photo Gallery多个SQL注入漏洞
CVE-2005-3989Avaya TN2602AP IP Media Resource 320 远程拒绝服务漏洞
CVE-2004-2643微软CABARC目录遍历漏洞
CVE-2004-2642Nathaniel Bray Yeemp文件Transfer公钥认证绕过漏洞
CVE-2004-2641Sun Fire/Netra单TOS选项IP包远程拒绝服务漏洞
CVE-2004-2644ASN.1 Compiler多个未明的漏洞
CVE-2004-2639Journalness帖子创建修改漏洞
CVE-2004-2638Admin Access With Levels Plug-in For osCommerce访问控制绕过漏洞
CVE-2004-2637Zonet无线路由器NAT实现设计缺陷漏洞
CVE-2004-2636Rit Research Labs TinyWeb Server未授权脚本泄露漏洞
CVE-2004-2635McAfee Security Installer Control System ActiveX信息披露漏洞
CVE-2004-2634IBM AIX Console命令多个符号链接漏洞
CVE-2004-2633Sesame未授权库访问漏洞
CVE-2004-2632phpMyAdmin多个输入验证漏洞
CVE-2004-2631phpMyAdmin多个输入验证漏洞

Showing top 20 of 55 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2004-2628

No comments yet


Leave a comment