QID 150508
Date Published: 2022-05-09
QID 150508: Lighttpd Server Log Injection Vulnerability (CVE-2015-3200)
Lighttpd is a secure, fast, compliant, and very flexible web-server that has been optimized for high-performance environment.
The installed version of lighttpd allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.
Affected versions:
lighttpd before 1.4.35
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks the response headers to confirm if the host is running vulnerable version of lighttpd Server.
Successful exploitation of this vulnerability allows an unauthorized attacker to modify system information.
Solution
Customers are advised to update lighttpd to new version. For more information related to this vulnerability please refer lighttpd Security advisory
Vendor References
- Bug 2646 -
redmine.lighttpd.net/issues/2646
CVEs related to QID 150508
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Bug 2646 |
|