Unrated severityNVD Advisory· Published Jun 17, 2005· Updated Apr 16, 2026
CVE-2005-2008
CVE-2005-2008
Description
Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).
Affected products
6cpe:2.3:a:yaws:webserver:1.50:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:yaws:webserver:1.50:*:*:*:*:*:*:*
- cpe:2.3:a:yaws:webserver:1.51:*:*:*:*:*:*:*
- cpe:2.3:a:yaws:webserver:1.52:*:*:*:*:*:*:*
- cpe:2.3:a:yaws:webserver:1.53:*:*:*:*:*:*:*
- cpe:2.3:a:yaws:webserver:1.54:*:*:*:*:*:*:*
- cpe:2.3:a:yaws:webserver:1.55:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- secunia.com/advisories/15740nvdPatchVendor Advisory
- yaws.hyber.org/yaws-1.55_to_1.56.patchnvdPatchVendor Advisory
- www.osvdb.org/17375nvdVendor Advisory
- marc.infonvd
News mentions
0No linked articles in our index yet.