Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 34 min 105 bronnen 1 kritiek 32 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2015-3200

HIGH · 7.5 CVSS Gepubliceerd: CWE-74

Beschrijving

mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.

Vendors

Lighttpd Hp Oracle

Affected products

Lighttpd Virtual Customer Access System Solaris

References