Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-5533

The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.393
EPSS Ranking 97.1%
CVSS Severity
CVSS v2 Score 5.0
References
Products affected by CVE-2012-5533


Contact Us

Shodan ® - All rights reserved