CVE-2009-4490
EXPLOITEDmini_httpd 1.19 - Remote Command Execution via Terminal Emulator Escape Sequence
Title source: llmExploitation Summary
CVE-2009-4490 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including evilaliv3.
AI-analyzed exploit summary The exploit demonstrates a command injection vulnerability in Acme 'thttpd' and 'mini_httpd' by sending a crafted HTTP request containing terminal escape sequences. This allows arbitrary command execution in the terminal where the logfile is viewed.
Description
mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
Exploits (1)
The exploit demonstrates a command injection vulnerability in Acme 'thttpd' and 'mini_httpd' by sending a crafted HTTP request containing terminal escape sequences. This allows arbitrary command execution in the terminal where the logfile is viewed.