CVE-2007-5654: Infoleak
Published Oct 23, 2007
·Updated
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime Type Injection."
Affected Software
1 affected component
Litespeed Technologies Litespeed Web Server<=3.2.3
Event History
Oct 23, 2007
CVE Published
09:47 PM
Oct 24, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5654?
CVE-2007-5654 has been classified as a medium-risk vulnerability due to potential information disclosure.
2
How do I fix CVE-2007-5654?
To mitigate CVE-2007-5654, upgrade LiteSpeed Web Server to version 3.2.4 or later.
3
What type of attack does CVE-2007-5654 enable?
CVE-2007-5654 enables arbitrary MIME type usage, potentially allowing attackers to read sensitive files.
4
Which versions of LiteSpeed Web Server are affected by CVE-2007-5654?
LiteSpeed Web Server versions before 3.2.4 are affected by CVE-2007-5654.
5
Can CVE-2007-5654 be exploited remotely?
Yes, CVE-2007-5654 can be exploited remotely by an attacker submitting specially crafted requests.