CVE-2009-3902

Cherokee Web Server <0.5.4 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (slash backslash dot dot) in the URL.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Dr_IDE · textwebappswindows
https://www.exploit-db.com/exploits/9873

Scores

EPSS 0.0727
EPSS Percentile 91.5%

Classification

CWE
CWE-22
Status draft

Affected Products (1)

cherokee/cherokee_httpd

Timeline

Published Nov 06, 2009
Tracked Since Feb 18, 2026