Back

CVE-2001-1432

Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Published: Dec 29, 2001 Modified: Jun 16, 2026
CWE-22

CVSS Metrics

Affected Products (7)

Vendor Product Version
cherokee cherokee_httpd 0.1
cherokee cherokee_httpd 0.1.5
cherokee cherokee_httpd 0.1.6
cherokee cherokee_httpd 0.2
cherokee cherokee_httpd 0.2.5
cherokee cherokee_httpd 0.2.6
cherokee cherokee_httpd 0.2.7

GitHub Security Advisory GHSA-3vr7-vf47-wq6v

Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read...

Risk Scores

CVSS Score 7.8 / 10
EPSS Score 4.07%

Top 10% most likely to be exploited

Threat Score 32.4 / 100

Data Sources

NVD EPSS GitHub