38628vdb entry
http://osvdb.org/38628 CVE-2007-3327
BugHunter HTTP Server 1.6.2 - Parse Error Information Disclosure
Record summary
CVE-2007-3327 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
httpsv.exe in HTTP Server 1.6.2 allows remote attackers to obtain sensitive information (script source code) via a URI with a trailing %20 (encoded space).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBBugHunter HTTP Server 1.6.2 - Parse Error Information DisclosureExploitDB exploitby PriliNot analyzed1 file
References
62828Third-party advisory
http://securityreason.com/securityalert/2828 20070620 HTTP SERVER (httpsv1.6.2) source code disclosuremailing list
http://www.securityfocus.com/archive/1/471876/100/0/threaded 24566vdb entry
http://www.securityfocus.com/bid/24566 http-extension-source-code-disclosure(34960)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/34960 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-3327