lighttpd是德国Jan Kneschke个人开发者的一款开源的Web服务器。 Lighttpd 1.4.56 到 1.4.58 版本存在安全漏洞,该漏洞源于 connections.c 中的 connection_read_header_more 有一个拼写错误,会破坏对大型标头的多个读取操作的使用。远程攻击者利用该漏洞可导致拒绝服务(卡住的连接消耗 CPU)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2022-30780 - lighttpd remote denial of service | https://github.com/p0dalirius/CVE-2022-30780-lighttpd-denial-of-service | POC Details |
| 2 | Lighttpd CVE-2022-30780 checker | https://github.com/xiw1ll/CVE-2022-30780_Checker | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-44266 | GUnet Open eClass Platform 跨站脚本漏洞 | |
| CVE-2021-41502 | Subrion CMS 跨站脚本漏洞 | |
| CVE-2021-41738 | Zeroshell 操作系统命令注入漏洞 |
No comments yet