CVE-2006-5216
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 64%
from disclosure to weapon1308 days
Published on NVDOct 9
1st PoC+1308d
metasploitOct 6
exploitation probability
64%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary code via a long URI.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/2482unverifiedexploitdbwww.exploit-db.com/exploits/16759unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://exploitlabs.com/files/advisories/EXPL-A-2006-005-shttpd.txthttp://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050146.htmlhttp://secunia.com/advisories/22294http://securitytracker.com/id?1017088https://exchange.xforce.ibmcloud.com/vulnerabilities/29368https://www.exploit-db.com/exploits/2482http://www.securityfocus.com/bid/20393http://www.vupen.com/english/advisories/2006/3939