VYPR

Muhttpd

by Inglorion

CVEs (1)

  • CVE-2022-31793HigAug 4, 2022
    risk 0.50cvss 7.5epss 0.16

    do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443,…