Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lighttpd 'mod_access.c'信息泄露漏洞
Vulnerability Description
lighttpd是德国软件开发者Jan Kneschke所研发的一款开源的Web服务器,它的主要特点是仅需少量的内存及CPU资源即可达到同类网页服务器的性能。 Lighttpd的mod_access.c中存在信息泄露漏洞。Lighttpd没有正确地解析HTTP头,如果用户在HTTP请求中向URL添加了"/"的话,就可以通过这样的请求访问受限制的文件。
CVSS Information
N/A
Vulnerability Type
N/A