Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2007-3947 — Lighttpd vulnerability
6 documents6 sources
Severity
5.8MEDIUMNVD
EPSS
16.5%
top 5.08%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 24
Latest updateMay 1
Description
request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault.
CVSS vector
AV:N/AC:M/C:P/I:N/A:PExploitability: 8.6 | Impact: 4.9
Affected Packages3 packages
🔴Vulnerability Details
2💥Exploits & PoCs
1Exploit-DB▶
Lighttpd 1.4.15 - Multiple Code Execution / Denial of Service / Information Disclosure Vulnerabilities↗2007-04-16
📋Vendor Advisories
1Debian▶
CVE-2007-3947: lighttpd - request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of servic...↗2007