cbcvebase.
CVE-2007-3949
published 2007-07-24

CVE-2007-3949: mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.

PriorityP340high8.3CVSS 2.0
AVNACMAuNCPIPAC
EPSS
3.30%
87.1th percentile
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianlighttpd< lighttpd 1.4.16-1 (bookworm)lighttpd 1.4.16-1 (bookworm)
lighttpdlighttpd<= 1.4.15
lighttpdlighttpd>= 0 < 1.4.16-11.4.16-1
lighttpdlighttpd>= 0 < 1.4.16-11.4.16-1
lighttpdlighttpd>= 0 < 1.4.16-11.4.16-1
lighttpdlighttpd>= 0 < 1.4.16-11.4.16-1

CVSS provenance

nvdv2.08.3HIGHAV:N/AC:M/Au:N/C:P/I:P/A:C
osv8.3HIGH
vendor_debian8.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.