Executive brief
A directory traversal vulnerability exists in the http_verify() function of Nostromo nhttpd through version 1.9.6. An attacker can exploit this via a crafted HTTP request to bypass directory restrictions and achieve remote code execution on non-chrooted servers.
Affected products
- Nazgul nhttpd up to 1.9.6
Timeline
- 2019-10-31: disclosed: Initial CVE modification date recorded by MITRE
- 2024-11-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-11-07: advisory: NVD publication date