CVE-2007-3949 - CERT CVE
ID CVE-2007-3949
Sažetak mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.
Reference
CVSS
Base: 8.3
Impact: 8.5
Exploitability:8.6
Pristup
VektorSloženostAutentikacija
NETWORK MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL COMPLETE
CVSS vektor AV:N/AC:M/Au:N/C:P/I:P/A:C
Zadnje važnije ažuriranje 15-10-2018 - 21:32
Objavljeno 24-07-2007 - 00:30