CVE Database
/

CVE-2008-0338

Back to search

CVE-2008-0338

Published: Jan 17, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI.

VendorProductVersions

n/a

n/a

affected
n/a

References

4923
exploit
x_refsource_EXPLOIT-DB
ADV-2008-0176
vdb-entry
x_refsource_VUPEN
28512
third-party-advisory
x_refsource_SECUNIA
27319
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now