Security Advisory

CVE-2010-10012

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-07-23 13:53:38
Last updated 2026-04-07 14:01:36
Assigner VulnCheck
State PUBLISHED

Description

A path traversal vulnerability exists in httpdasm version 0.92, a lightweight Windows HTTP server, that allows unauthenticated attackers to read arbitrary files on the host system. By sending a specially crafted GET request containing a sequence of URL-encoded backslashes and directory traversal patterns, an attacker can escape the web root and access sensitive files outside of the intended directory.