Lucene search

K
nessusTenable8159.PRM
HistoryMar 13, 2014 - 12:00 a.m.

lighttpd < 1.4.35 Multiple Vulnerabilities

2014-03-1300:00:00
Tenable
www.tenable.com
74

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.96

Percentile

99.5%

Versions older than 1.4.35 are vulnerable to the following issues:

  • Insufficient user input sanitation on the hostname in the ‘mod_mysql_vhost’ module could be leveraged for a SQL injection attack (CVE-2014-2323)

  • Insufficient user input sanitation on the hostname in ‘mod_evhost’ and ‘mod_simple_vhost’ modules could be leveraged for directory traversal attacks (CVE-2014-2324)

Binary data 8159.prm
VendorProductVersionCPE
lighttpdlighttpdcpe:/a:lighttpd:lighttpd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.96

Percentile

99.5%