Release date:
Updated on:
Affected Systems:
Lighttpd lighttpd 1.4.x
Lighttpd lighttpd 1.3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66153
CVE (CAN) ID: CVE-2014-2323
Lighttpd is a lightweight open source Web Server software package.
In versions earlier than lighttpd 1.4.35, multiple SQL Injection Vulnerabilities exist. Remote attackers can exploit these vulnerabilities to control applications and perform unauthorized database operations.
<* Source: Jann Horn
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Lighttpd
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.lighttpd.net/
Lighttpd details: click here
Lighttpd: click here
Build Lighttpd in CentOS 5.6
Cacti monitoring Lighttpd
Ubuntu manual compilation and installation of Lighttpd configuration to run PHP
Port Lighttpd Web server to ARM Linux
Build a Lighttpd + PHP + MySQL environment in Ubuntu
Install Lighttpd + PHP5 + MySQL on CentOS 5.6
Lighttpd performs anti-leech protection on compressed video files