关键漏洞信息 漏洞ID: CVE-2007-5685 CVSS 2.0 Base Score: 5 Access Vector: Network Access Complexity: Low Authentication: None Confidentiality Impact: Partial Integrity Impact: None Availability Impact: None CVSS 2.0 Temporal Score: 4.4 Exploitability: High Remediation Level: Official Fix Report Confidence: Confirmed Description: The shthttp safe_path directive does not properly restrict HTTP requests containing "dot-dot" sequences ( ) to traverse directories and view arbitrary files on the system. Consequences: Obtain Information Remedy: Upgrade to the latest version of shthttp (0.0.5 or later), available from the Shttplib Web site. See References. Affected Products: Vito Caputo shthttp 0.0.4 References: BugTraq Mailing List, Thu Oct 25 2007 - 12:46:26 CDT Shttplib Web site BID-26212 CVE-2007-5685