CVE-2010-2320

Exp

bozotic HTTP server (aka bozohttpd) before 20100621 allows remote attackers to list the contents of home directories, and determine the existence of user accounts, via multiple requests for URIs beginning with /~ sequences.

Published: 2010-08-02 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2010-2320 is rated Exploit Available (58.6/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.62%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2010-2320

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2010-2320

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-03-30 0.70% 0.62% -0.08%
2 2025-03-29 0.62% 0.70% +0.08%
3 2025-03-17 0.62%

Full EPSS history (7 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2010-2320

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2010-2320

OS Trackers for CVE-2010-2320

vendor priority summary link
ubuntu low CVE-2010-2320 low priority: Ubuntu including 1 source packages (bozohttpd), 13 status rows across 13 suites (dapper, hardy, jaunty, karmic, lucid, maverick, natty, oneiric, precise, quantal, raring, saucy, upstream): not-affected 7, ignored 5, needs-triage 1. https://ubuntu.com/security/CVE-2010-2320

Affected software / configurations for CVE-2010-2320

Vendor Product Version Raw CPE
eterna bozohttpd <= 20100617 cpe:2.3:a:eterna:bozohttpd:*:*:*:*:*:*:*:*
eterna bozohttpd 19990519 cpe:2.3:a:eterna:bozohttpd:19990519:*:*:*:*:*:*:*
eterna bozohttpd 20000421 cpe:2.3:a:eterna:bozohttpd:20000421:*:*:*:*:*:*:*
eterna bozohttpd 20000426 cpe:2.3:a:eterna:bozohttpd:20000426:*:*:*:*:*:*:*
eterna bozohttpd 20000427 cpe:2.3:a:eterna:bozohttpd:20000427:*:*:*:*:*:*:*
eterna bozohttpd 20000815 cpe:2.3:a:eterna:bozohttpd:20000815:*:*:*:*:*:*:*
eterna bozohttpd 20000825 cpe:2.3:a:eterna:bozohttpd:20000825:*:*:*:*:*:*:*
eterna bozohttpd 20010610 cpe:2.3:a:eterna:bozohttpd:20010610:*:*:*:*:*:*:*
eterna bozohttpd 20010812 cpe:2.3:a:eterna:bozohttpd:20010812:*:*:*:*:*:*:*
eterna bozohttpd 20010922 cpe:2.3:a:eterna:bozohttpd:20010922:*:*:*:*:*:*:*
eterna bozohttpd 20020710 cpe:2.3:a:eterna:bozohttpd:20020710:*:*:*:*:*:*:*
eterna bozohttpd 20020730 cpe:2.3:a:eterna:bozohttpd:20020730:*:*:*:*:*:*:*
eterna bozohttpd 20020803 cpe:2.3:a:eterna:bozohttpd:20020803:*:*:*:*:*:*:*
eterna bozohttpd 20020804 cpe:2.3:a:eterna:bozohttpd:20020804:*:*:*:*:*:*:*
eterna bozohttpd 20020823 cpe:2.3:a:eterna:bozohttpd:20020823:*:*:*:*:*:*:*
eterna bozohttpd 20020913 cpe:2.3:a:eterna:bozohttpd:20020913:*:*:*:*:*:*:*
eterna bozohttpd 20021106 cpe:2.3:a:eterna:bozohttpd:20021106:*:*:*:*:*:*:*
eterna bozohttpd 20030313 cpe:2.3:a:eterna:bozohttpd:20030313:*:*:*:*:*:*:*
eterna bozohttpd 20030409 cpe:2.3:a:eterna:bozohttpd:20030409:*:*:*:*:*:*:*
eterna bozohttpd 20030626 cpe:2.3:a:eterna:bozohttpd:20030626:*:*:*:*:*:*:*
eterna bozohttpd 20031005 cpe:2.3:a:eterna:bozohttpd:20031005:*:*:*:*:*:*:*
eterna bozohttpd 20040218 cpe:2.3:a:eterna:bozohttpd:20040218:*:*:*:*:*:*:*
eterna bozohttpd 20040808 cpe:2.3:a:eterna:bozohttpd:20040808:*:*:*:*:*:*:*
eterna bozohttpd 20050410 cpe:2.3:a:eterna:bozohttpd:20050410:*:*:*:*:*:*:*
eterna bozohttpd 20060517 cpe:2.3:a:eterna:bozohttpd:20060517:*:*:*:*:*:*:*
eterna bozohttpd 20060710 cpe:2.3:a:eterna:bozohttpd:20060710:*:*:*:*:*:*:*
eterna bozohttpd 20080303 cpe:2.3:a:eterna:bozohttpd:20080303:*:*:*:*:*:*:*
eterna bozohttpd 20090417 cpe:2.3:a:eterna:bozohttpd:20090417:*:*:*:*:*:*:*
eterna bozohttpd 20090522 cpe:2.3:a:eterna:bozohttpd:20090522:*:*:*:*:*:*:*
eterna bozohttpd 20100509 cpe:2.3:a:eterna:bozohttpd:20100509:*:*:*:*:*:*:*
eterna bozohttpd 20100512 cpe:2.3:a:eterna:bozohttpd:20100512:*:*:*:*:*:*:*

References for CVE-2010-2320

cvelogic Threat Intelligence