Back
CVE-2001-1432
Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
Published: Dec 29, 2001
Modified: Jun 16, 2026
CWE-22
CVSS Metrics
Affected Products (7)
| Vendor | Product | Version |
|---|---|---|
| cherokee | cherokee_httpd | 0.1 |
| cherokee | cherokee_httpd | 0.1.5 |
| cherokee | cherokee_httpd | 0.1.6 |
| cherokee | cherokee_httpd | 0.2 |
| cherokee | cherokee_httpd | 0.2.5 |
| cherokee | cherokee_httpd | 0.2.6 |
| cherokee | cherokee_httpd | 0.2.7 |
GitHub Security Advisory GHSA-3vr7-vf47-wq6v
Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read...
References (8)
- http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0085.html Exploit
- http://www.kb.cert.org/vuls/id/464827 US Government Resource
- http://www.securityfocus.com/bid/3772 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7799
- http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0085.html Exploit
- http://www.kb.cert.org/vuls/id/464827 US Government Resource
- http://www.securityfocus.com/bid/3772 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7799
Risk Scores
CVSS Score
7.8 / 10
EPSS Score
4.07%
Top 10% most likely to be exploited
Threat Score
32.4 / 100
Data Sources
NVD
EPSS
GitHub