CVE-2006-0814: Medium severity Lighttpd Lighttpd vulnerability
response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests that contain trailing (1) "." (dot) and (2) space characters, which are ignored by Windows, as demonstrated by PHP files.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0814?
CVE-2006-0814 is considered a medium severity vulnerability due to its potential for unauthorized access to sensitive files.
How do I fix CVE-2006-0814?
To mitigate CVE-2006-0814, it is recommended to upgrade to a patched version of Lighttpd above 1.4.10.
Which versions of Lighttpd are affected by CVE-2006-0814?
CVE-2006-0814 affects Lighttpd versions 1.4.10 and possibly earlier, especially when running on Windows.
Can CVE-2006-0814 be exploited remotely?
Yes, CVE-2006-0814 allows remote attackers to read arbitrary source code, making it exploitable from outside the network.
What are the possible consequences of exploiting CVE-2006-0814?
Exploiting CVE-2006-0814 can lead to unauthorized disclosure of sensitive source code, potentially exposing vulnerabilities in the application.