漏洞描述
A SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name (related to request_check_hostname).
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2014-2323↗download.lighttpd.nethttps://download.lighttpd.net/lighttpd/security/lighttpd_sa_2014_01.txt↗www.lighttpd.nethttp://www.lighttpd.net/2014/3/12/1.4.35/↗seclists.orghttp://seclists.org/oss-sec/2014/q1/561↗jvn.jphttp://jvn.jp/en/jp/JVN37417423/index.html↗