Описание
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
lighttpd | fixed | 1.4.16-1 | package |
EPSS
Процентиль: 70%
0.00641
Низкий
Связанные уязвимости
ubuntu
около 18 лет назад
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.
nvd
около 18 лет назад
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.
github
больше 3 лет назад
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.
EPSS
Процентиль: 70%
0.00641
Низкий