PT-2005-1513 · Lighttpd · Lighttpd
Published
2005-02-16
·
Updated
2008-09-05
·
CVE-2005-0453
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Lighttpd versions 1.3.7 and earlier
Description
The issue arises from the buffer urldecode function not properly handling control characters. This allows remote attackers to obtain the source code for CGI and FastCGI scripts by including a %00 (null) character after the file extension in a URL.
Recommendations
For Lighttpd versions 1.3.7 and earlier, update to a version that fixes the buffer urldecode function issue to prevent remote attackers from obtaining source code for scripts.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lighttpd