Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3mcq-rwcj-x5r6

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for ".php" names.

LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for ".php" names.

EPSS

Процентиль: 57%
0.00353
Низкий

Связанные уязвимости

nvd
почти 20 лет назад

LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for ".php" names.

EPSS

Процентиль: 57%
0.00353
Низкий