First published: Wed Feb 16 2005(Updated: )
The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lighttpd Lighttpd | =1.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.