LiteSpeed Web Server Source Code Information Disclosure Vulnerability
BID:40815
Info
LiteSpeed Web Server Source Code Information Disclosure Vulnerability
| Bugtraq ID: | 40815 |
| Class: | Design Error |
| CVE: |
CVE-2010-2333 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Kingcope |
| Vulnerable: |
LiteSpeed Web Server 4.0.14 LiteSpeed Web Server 4.0.12 |
| Not Vulnerable: |
LiteSpeed Web Server 4.0.15 |
Discussion
LiteSpeed Web Server Source Code Information Disclosure Vulnerability
LiteSpeed Web Server is prone to a vulnerability that lets attackers access source code files.
An attacker can exploit this vulnerability to retrieve certain files from the vulnerable computer in the context of the webserver process. Information obtained may aid in further attacks.
LiteSpeed Web Server versions prior to 4.0.15 are affected.
LiteSpeed Web Server is prone to a vulnerability that lets attackers access source code files.
An attacker can exploit this vulnerability to retrieve certain files from the vulnerable computer in the context of the webserver process. Information obtained may aid in further attacks.
LiteSpeed Web Server versions prior to 4.0.15 are affected.
Exploit / POC
LiteSpeed Web Server Source Code Information Disclosure Vulnerability
Attackers can exploit this vulnerability via a browser.
The following exploits are available:
Attackers can exploit this vulnerability via a browser.
The following exploits are available:
Solution / Fix
LiteSpeed Web Server Source Code Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
LiteSpeed Web Server Source Code Information Disclosure Vulnerability
References:
References:
- LiteSpeed Web Server 4.0.15 Released (LiteSpeed)
- Vendor Homepage (LiteSpeed Technologies)