Smallsrv Small HTTP Server
cpe:2.3:a:smallsrv:small_http_server:*:*:*:*:*:*:*
- 3.06.36
A vulnerability exists in Small HTTP Server version 3.06.36 due to an unquoted service path in the executable 'http.exe service'. This misconfiguration allows local attackers to place a malicious executable with the same name in a higher priority directory, leading the service to execute the malicious file instead of the legitimate one. Exploitation of this vulnerability could result in arbitrary code execution, unauthorized system access, or service disruption.
Exploitation of this vulnerability could allow arbitrary code execution, unauthorized access to the system, or disruption of the service.
Users are advised to update to Small HTTP Server version 3.06.38, ensure that service paths are properly quoted, and restrict physical and network access to the system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.