PT-2008-5610 · Lighttpd · Lighttpd

Anders

·

Publicado

2008-10-03

·

Atualizado

2018-11-29

·

CVE-2008-4360

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: lighttpd versions prior to 1.4.20
Description: The issue allows remote attackers to bypass intended access restrictions due to case-sensitive comparisons on filename components in configuration options when a case-insensitive operating system or filesystem is used. This can be demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
Recommendations: For versions prior to 1.4.20, update to version 1.4.20 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4360
DSA-1645-1

Produtos afetados

Lighttpd