Main
Vulnerability Database
Exploits
ID:3629 - Exploit for Path traversal in lighttpd - CVE-2014-2324
ID:3629 - Exploit for Path traversal in lighttpd - CVE-2014-2324
Published: July 29, 2020
Vulnerability identifier: #VU32560
Vulnerability risk: Medium
CVE-ID: CVE-2014-2324
CWE-ID: CWE-22
Exploitation vector: Remote access
Vulnerable software:
lighttpd
lighttpd
Link to public exploit:
Vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
Remediation
Install update from vendor's website.