PT-2008-5610 · Lighttpd · Lighttpd
Anders
·
Publicado
2008-10-03
·
Atualizado
2018-11-29
·
CVE-2008-4360
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
lighttpd versions prior to 1.4.20
Description:
The issue allows remote attackers to bypass intended access restrictions due to case-sensitive comparisons on filename components in configuration options when a case-insensitive operating system or filesystem is used. This can be demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
Recommendations:
For versions prior to 1.4.20, update to version 1.4.20 or later to resolve the issue.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Lighttpd