CVE-2002-1864
sws_simple_web_server 0.0.4-0.1.0 - Unauthenticated Directory Traversal via Dot-Dot Sequence
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-1864.
PoCs published by CwG GeNiuS, sinn3r, including Metasploit module auxiliary/scanner/http/simple_webserver_traversal.
AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability in Simple Web Server 2.3-RC1 by sending crafted HTTP requests with traversal sequences to retrieve arbitrary files from the server. It includes custom parsing logic to handle the server's non-standard HTTP responses.
Description
Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP request.
Exploits (1)
This Metasploit module exploits a directory traversal vulnerability in Simple Web Server 2.3-RC1 by sending crafted HTTP requests with traversal sequences to retrieve arbitrary files from the server. It includes custom parsing logic to handle the server's non-standard HTTP responses.