CVE-2006-0760: Low severity Lighttpd Lighttpd vulnerability
LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for ".php" names.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0760?
CVE-2006-0760 has been classified as a medium severity vulnerability due to its potential to expose sensitive information without proper authorization.
How do I fix CVE-2006-0760?
To fix CVE-2006-0760, upgrade to LightTPD version 1.4.9 or later, which addresses this vulnerability.
What versions of LightTPD are affected by CVE-2006-0760?
CVE-2006-0760 affects LightTPD versions 1.4.8 and earlier.
What kind of attacks can exploit CVE-2006-0760?
Attackers can exploit CVE-2006-0760 by manipulating URL file extensions with unexpected capitalization to bypass security checks.
Is CVE-2006-0760 a critical vulnerability?
No, CVE-2006-0760 is not considered critical, but it can still lead to the exposure of sensitive information.