← back
CVE-2009-4491

CVE-2009-4491

CVSS 9.8 CRITICALEPSS 13.5%CWE-94
Vexday Risk Score
53Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.8EPSS 13.5%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
11 Jan 2010Public PoC
13 Jan 2010Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →