cbcvebase.
CVE-2013-1427
published 2013-03-21

CVE-2013-1427: The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which…

PriorityP48low1.9CVSS 2.0
AVLACMAuNCNIPAN
EPSS
0.35%
27.2th percentile
The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP control socket and perform unauthorized actions such as forcing the use of a different version of PHP via a symlink attack or a race condition.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlighttpd< lighttpd 1.4.31-4 (bookworm)lighttpd 1.4.31-4 (bookworm)
lighttpdlighttpd<= 1.4.27
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd
lighttpdlighttpd

CVSS provenance

nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
osv1.9LOW
vendor_debian1.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.