Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Litespeed Technologies Subscribe
Filtered by product Litespeed Web Server
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-5654 1 Litespeed Technologies 1 Litespeed Web Server 2017-09-28 5.0 MEDIUM N/A
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime Type Injection."
CVE-2005-3695 1 Litespeed Technologies 1 Litespeed Web Server 2011-03-07 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the m parameter.