← Back

CVE-2014-2324

nvd nist
Published: Mar 14, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.

Affected (10)

Products: Lighttpd: Lighttpd · Debian: Debian Linux · Opensuse: Opensuse · +2 more
Show all products
1 product
Lighttpd
1 product
Debian Linux
1 product
Opensuse
2 products
1 product
Sv Cpt Mc310 Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.4.35
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 6.0
Version 7.0
Version 8.0
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 11.4
Version 12.3
Version 13.1
Version 11 sp3
Version 11 sp3
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.5
Running on/withPlatform Versions
Contec
Sv Cpt Mc310
All versions

References (26)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Not Applicable
Source: cve@mitre.org
Not Applicable
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.