Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
                
            References
                    Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Configuration 2 (hide)
                                
                                
  | 
                        
Configuration 3 (hide)
                                
                                
  | 
                        
Configuration 4 (hide)
| AND | 
                                
                                
 
  | 
                        
Information
                Published : 2014-03-14 08:55
Updated : 2021-02-24 12:06
NVD link : CVE-2014-2324
Mitre link : CVE-2014-2324
JSON object : View
CWE
                
                    
                        
                        CWE-22
                        
            Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
                contec
- sv-cpt-mc310_firmware
 - sv-cpt-mc310
 
lighttpd
- lighttpd
 
suse
- linux_enterprise_software_development_kit
 - linux_enterprise_high_availability_extension
 
debian
- debian_linux
 
opensuse
- opensuse
 


