ID:3629 - Exploit for Path traversal in lighttpd - CVE-2014-2324

 
Main Vulnerability Database Exploits ID:3629 - Exploit for Path traversal in lighttpd - CVE-2014-2324

ID:3629 - Exploit for Path traversal in lighttpd - CVE-2014-2324

Published: July 29, 2020


Vulnerability identifier: #VU32560
Vulnerability risk: Medium
CVE-ID: CVE-2014-2324
CWE-ID: CWE-22
Exploitation vector: Remote access
Vulnerable software:
lighttpd

Link to public exploit:


Vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.


Remediation

Install update from vendor's website.