Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-4359
Description:lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.1.2008.1645  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-4359
BugTraq ID: 31599
http://www.securityfocus.com/bid/31599
Bugtraq: 20081030 rPSA-2008-0309-1 lighttpd (Google Search)
http://www.securityfocus.com/archive/1/497932/100/0/threaded
Debian Security Information: DSA-1645 (Google Search)
http://www.debian.org/security/2008/dsa-1645
http://security.gentoo.org/glsa/glsa-200812-04.xml
http://openwall.com/lists/oss-security/2008/09/30/1
http://openwall.com/lists/oss-security/2008/09/30/2
http://openwall.com/lists/oss-security/2008/09/30/3
http://secunia.com/advisories/32069
http://secunia.com/advisories/32132
http://secunia.com/advisories/32480
http://secunia.com/advisories/32834
http://secunia.com/advisories/32972
SuSE Security Announcement: SUSE-SR:2008:026 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html
http://www.vupen.com/english/advisories/2008/2741
XForce ISS Database: lighttpd-urlredirect-rewrite-info-disclosure(45690)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45690




© 1998-2025 E-Soft Inc. All rights reserved.