CVE-2014-2324
HP Security Bulletin HPSBGN03191 1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
MĂșltiples vulnerabilidades de salto de directorio en (1) mod_evhost y (2) mod_simple_vhost en lighttpd anterior a 1.4.35 permiten a atacantes remotos leer archivos arbitrarios a travĂ©s de un .. (punto punto) en el nombre de host, relacionado con request_check_hostname.
A potential security vulnerabilities have been identified with HP Remote Device Access: Virtual Customer Access System (vCAS) running lighttpd. These vulnerabilities could be exploited remotely resulting in disclosure of information, elevation of privilege, SQL injection, or to create a Denial of Service (DoS). These vulnerabilities include the SSLv3 vulnerability known as "Padding Oracle on Downgraded Legacy Encryption" also known as "Poodle", which could be exploited remotely to allow disclosure of information. SSLv3 is enabled by default in the lighttpd based vCAS Web Server. Revision 1 of this advisory.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-03-12 CVE Reserved
- 2014-03-13 CVE Published
- 2023-12-07 First Exploit
- 2024-08-06 CVE Updated
- 2025-05-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://jvn.jp/en/jp/JVN37417423/index.html | Third Party Advisory | |
http://seclists.org/oss-sec/2014/q1/564 | Mailing List |
|
http://secunia.com/advisories/57404 | Not Applicable | |
http://secunia.com/advisories/57514 | Not Applicable | |
http://www.securityfocus.com/bid/66157 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/sp4c30x1/uc_httpd_exploit | 2023-12-07 | |
http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2014_01.txt | 2024-08-06 | |
http://seclists.org/oss-sec/2014/q1/561 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://www.lighttpd.net/2014/3/12/1.4.35 | 2021-02-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Contec Search vendor "Contec" | Sv-cpt-mc310 Firmware Search vendor "Contec" for product "Sv-cpt-mc310 Firmware" | < 6.5 Search vendor "Contec" for product "Sv-cpt-mc310 Firmware" and version " < 6.5" | - |
Affected
| in | Contec Search vendor "Contec" | Sv-cpt-mc310 Search vendor "Contec" for product "Sv-cpt-mc310" | - | - |
Safe
|
Lighttpd Search vendor "Lighttpd" | Lighttpd Search vendor "Lighttpd" for product "Lighttpd" | < 1.4.35 Search vendor "Lighttpd" for product "Lighttpd" and version " < 1.4.35" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 6.0 Search vendor "Debian" for product "Debian Linux" and version "6.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 7.0 Search vendor "Debian" for product "Debian Linux" and version "7.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 11.4 Search vendor "Opensuse" for product "Opensuse" and version "11.4" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 12.3 Search vendor "Opensuse" for product "Opensuse" and version "12.3" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 13.1 Search vendor "Opensuse" for product "Opensuse" and version "13.1" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Linux Enterprise High Availability Extension Search vendor "Suse" for product "Linux Enterprise High Availability Extension" | 11 Search vendor "Suse" for product "Linux Enterprise High Availability Extension" and version "11" | sp3 |
Affected
| ||||||
Suse Search vendor "Suse" | Linux Enterprise Software Development Kit Search vendor "Suse" for product "Linux Enterprise Software Development Kit" | 11 Search vendor "Suse" for product "Linux Enterprise Software Development Kit" and version "11" | sp3 |
Affected
|