Sploitus

CVE-2003-0899

2 known exploits for CVE-2003-0899

Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.

Affected products
Thttpd
Acme Thttpd
< 2.23
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
21.7% (97th percentile)
Weakness
CWE-131
NVD status
Modified
Published
2003-10-30
CVE-2003-0899 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2003-0899

Proof-of-concept code and exploit modules indexed by Sploitus