First published: Wed Feb 16 2005(Updated: )
The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fipsasp Fipscms Light | =1.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0453 has a medium severity rating due to its potential for information disclosure.
To address CVE-2005-0453, upgrade to Lighttpd version 1.3.8 or later, which resolves this vulnerability.
CVE-2005-0453 can allow remote attackers to access the source code of CGI and FastCGI scripts, posing a risk to sensitive information.
CVE-2005-0453 affects Lighttpd version 1.3.7 and earlier.
Yes, CVE-2005-0453 can be exploited remotely via specially crafted URLs containing a null character.