cbcvebase.
CVE-2014-2323
published 2014-03-14

CVE-2014-2323: SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlighttpd< lighttpd 1.4.33-1+nmu3 (bookworm)lighttpd 1.4.33-1+nmu3 (bookworm)
lighttpdlighttpd< 1.4.351.4.35
lighttpdlighttpd>= 0 < 1.4.33-1+nmu31.4.33-1+nmu3
lighttpdlighttpd>= 0 < 1.4.33-1+nmu31.4.33-1+nmu3
lighttpdlighttpd>= 0 < 1.4.33-1+nmu31.4.33-1+nmu3
lighttpdlighttpd>= 0 < 1.4.33-1+nmu31.4.33-1+nmu3
opensuseopensuse
opensuseopensuse
opensuseopensuse
suselinux_enterprise_high_availability_extension
suselinux_enterprise_software_development_kit

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL