Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for ".php" names.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LightTPD 信息泄露漏洞
Vulnerability Description
LightTPD 1.4.8及之前版本中的web root处于不区分大小写的文件系统中时,远程攻击者可以借助使用意外大写的文件扩展名绕过URL检查并获得敏感信息,如配置仅为".php"名称调用PHP解释程序时请求index.PHP所演示的那样。
CVSS Information
N/A
Vulnerability Type
N/A