Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lighttpd mod_auth模块权限许可和访问控制问题漏洞
Vulnerability Description
lighttpd是德国软件开发者Jan Kneschke所研发的一款开源的Web服务器,它的主要特点是仅需少量的内存及CPU资源即可达到同类网页服务器的性能。 lighttpd 1.4.36之前版本的mod_auth模块中存在安全漏洞。远程攻击者可借助不带冒号的Basic HTTP身份验证字符串利用该漏洞注入任意日志条目。
CVSS Information
N/A
Vulnerability Type
N/A