Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2009-4458 | thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. |
Tue, 17 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thttpd
Thttpd thttpd Http Server |
|
| CPEs | cpe:2.3:a:thttpd:thttpd_http_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Thttpd
Thttpd thttpd Http Server |
|
| Metrics |
ssvc
|
Wed, 07 Aug 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Thttpd
Thttpd thttpd Http Server |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T07:01:20.480Z
Reserved: 2009-12-30T00:00:00.000Z
Link: CVE-2009-4491
Updated: 2024-08-07T07:01:20.480Z
Status : Modified
Published: 2010-01-13T20:30:00.500
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-4491
No data.
OpenCVE Enrichment
No data.
EUVD