Lighttpd Remote Script Disclosure Vulnerability
BID:16893
Info
Lighttpd Remote Script Disclosure Vulnerability
| Bugtraq ID: | 16893 |
| Class: | Design Error |
| CVE: |
CVE-2006-0814 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2006 12:00AM |
| Updated: | Mar 05 2006 01:26AM |
| Credit: | Discovered by Tan Chew Keong, Secunia Research. |
| Vulnerable: |
lighttpd lighttpd 1.4.10 |
| Not Vulnerable: |
lighttpd lighttpd 1.4.10a |
Discussion
Lighttpd Remote Script Disclosure Vulnerability
The 'lighttpd' webserver is prone to an information-disclosure vulnerability. An attacker may obtain the source code of script files.
Scripts may contain sensitive information that may aid in further attacks launched against the target computer.
Versions prior to 1.4.10a of lighttpd for Windows are vulnerable.
The 'lighttpd' webserver is prone to an information-disclosure vulnerability. An attacker may obtain the source code of script files.
Scripts may contain sensitive information that may aid in further attacks launched against the target computer.
Versions prior to 1.4.10a of lighttpd for Windows are vulnerable.
Exploit / POC
Lighttpd Remote Script Disclosure Vulnerability
This issue can be exploited with a web browser.
This issue can be exploited with a web browser.
Solution / Fix
Lighttpd Remote Script Disclosure Vulnerability
Solution:
The vendor has reportedly released versions 1.4.10a to address this issue. Please see references for more information.
Solution:
The vendor has reportedly released versions 1.4.10a to address this issue. Please see references for more information.
References
Lighttpd Remote Script Disclosure Vulnerability
References:
References:
- Changeset 1005 (lighttpd)
- lighttpd Home Page (lighttpd)
- Secunia Research: Lighttpd Script Source Disclosure Vulnerability (Secunia Research
)