Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime Type Injection."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LiteSpeed Technologies LiteSpeed Web Server MIME种类文件代码注入漏洞
Vulnerability Description
LiteSpeed Web Server 3.2.4版本之前的版本允许远程攻击者可以借助一个"%00."序列和一个新的扩展名,如可以借助对.php%00.txt文件的请求,读取PHP源代码,触发任意MIME种类文件的运行,该漏洞又称"Mime Type Injection"。
CVSS Information
N/A
Vulnerability Type
N/A