Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-2628
CVE-2004-2628
Description
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:").
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- securitytracker.com/alerts/2004/Aug/1010850.htmlnvdExploit
- www.osvdb.org/displayvuln.phpnvdExploit
- www.securityfocus.com/bid/10862nvdExploit
- archives.neohapsis.com/archives/fulldisclosure/2004-08/0097.htmlnvd
- marc.infonvd
- www.acme.com/software/thttpd/nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/16882nvd
News mentions
0No linked articles in our index yet.