Lucene search

K
cveMitreCVE-2010-2320
HistoryAug 02, 2010 - 8:40 p.m.

CVE-2010-2320

2010-08-0220:40:01
CWE-264
mitre
web.nvd.nist.gov
22
cve-2010-2320
bozotic http server
bozohttpd
remote attackers
home directories
user accounts
security vulnerability
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0.011

Percentile

84.4%

bozotic HTTP server (aka bozohttpd) before 20100621 allows remote attackers to list the contents of home directories, and determine the existence of user accounts, via multiple requests for URIs beginning with /~ sequences.

Affected configurations

Nvd
Node
eternabozohttpdRange20100617
OR
eternabozohttpdMatch19990519
OR
eternabozohttpdMatch20000421
OR
eternabozohttpdMatch20000426
OR
eternabozohttpdMatch20000427
OR
eternabozohttpdMatch20000815
OR
eternabozohttpdMatch20000825
OR
eternabozohttpdMatch20010610
OR
eternabozohttpdMatch20010812
OR
eternabozohttpdMatch20010922
OR
eternabozohttpdMatch20020710
OR
eternabozohttpdMatch20020730
OR
eternabozohttpdMatch20020803
OR
eternabozohttpdMatch20020804
OR
eternabozohttpdMatch20020823
OR
eternabozohttpdMatch20020913
OR
eternabozohttpdMatch20021106
OR
eternabozohttpdMatch20030313
OR
eternabozohttpdMatch20030409
OR
eternabozohttpdMatch20030626
OR
eternabozohttpdMatch20031005
OR
eternabozohttpdMatch20040218
OR
eternabozohttpdMatch20040808
OR
eternabozohttpdMatch20050410
OR
eternabozohttpdMatch20060517
OR
eternabozohttpdMatch20060710
OR
eternabozohttpdMatch20080303
OR
eternabozohttpdMatch20090417
OR
eternabozohttpdMatch20090522
OR
eternabozohttpdMatch20100509
OR
eternabozohttpdMatch20100512
VendorProductVersionCPE
eternabozohttpd*cpe:2.3:a:eterna:bozohttpd:*:*:*:*:*:*:*:*
eternabozohttpd19990519cpe:2.3:a:eterna:bozohttpd:19990519:*:*:*:*:*:*:*
eternabozohttpd20000421cpe:2.3:a:eterna:bozohttpd:20000421:*:*:*:*:*:*:*
eternabozohttpd20000426cpe:2.3:a:eterna:bozohttpd:20000426:*:*:*:*:*:*:*
eternabozohttpd20000427cpe:2.3:a:eterna:bozohttpd:20000427:*:*:*:*:*:*:*
eternabozohttpd20000815cpe:2.3:a:eterna:bozohttpd:20000815:*:*:*:*:*:*:*
eternabozohttpd20000825cpe:2.3:a:eterna:bozohttpd:20000825:*:*:*:*:*:*:*
eternabozohttpd20010610cpe:2.3:a:eterna:bozohttpd:20010610:*:*:*:*:*:*:*
eternabozohttpd20010812cpe:2.3:a:eterna:bozohttpd:20010812:*:*:*:*:*:*:*
eternabozohttpd20010922cpe:2.3:a:eterna:bozohttpd:20010922:*:*:*:*:*:*:*
Rows per page:
1-10 of 311

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0.011

Percentile

84.4%

Related for CVE-2010-2320