← Back

CVE-2010-2320

nvd nist
Published: Aug 2, 2010Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

bozotic HTTP server (aka bozohttpd) before 20100621 allows remote attackers to list the contents of home directories, and determine the existence of user accounts, via multiple requests for URIs beginning with /~ sequences.

Affected (31)

Products: Eterna: Bozohttpd
1 product
Bozohttpd
Configuration A
31 vulnerable
Vulnerable SoftwareAffected Versions
Eterna
Up to 20100617
Version 19990519
Version 20000421
Version 20000426
Version 20000427
Version 20000815
Version 20000825
Version 20010610
Version 20010812
Version 20010922
Version 20020710
Version 20020730
Version 20020803
Version 20020804
Version 20020823
Version 20020913
Version 20021106
Version 20030313
Version 20030409
Version 20030626
Version 20031005
Version 20040218
Version 20040808
Version 20050410
Version 20060517
Version 20060710
Version 20080303
Version 20090417
Version 20090522
Version 20100509
Version 20100512

Related CWEs

References (12)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.