Description
ACME mini_httpd is a minimalistic web server designed for optimal performance, high security, and as little use of system resources as possible.
ACME mini_httpd before version 1.30 lets remote users read arbitrary files via a logical bug.
Remediation
Upgrade to the latest version of ACME mini_httpd. This issue was fixed in version 1.30.
References
Related Vulnerabilities
WordPress Plugin Zingiri Web Shop 'abspath' Parameter Remote File Include (2.4.6)
Ghost CMS Theme Path Traversal (CVE-2023-32235)
WordPress 4.3.x Directory Traversal (4.3 - 4.3.33)
WordPress Plugin Popup-Popup More Popups Directory Traversal (2.2.4)
WordPress Duplicator plugin Unauthenticated Arbitrary File Download