Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2014-2323
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.917
EPSS Ranking
99.7%
CVSS Severity
CVSS v3 Score
9.8
CVSS v2 Score
7.5
References
http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2014_01.txt
http://jvn.jp/en/jp/JVN37417423/index.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00023.html
http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00006.html
http://marc.info/?l=bugtraq&m=141576815022399&w=2
http://seclists.org/oss-sec/2014/q1/561
http://seclists.org/oss-sec/2014/q1/564
http://secunia.com/advisories/57404
http://secunia.com/advisories/57514
http://www.debian.org/security/2014/dsa-2877
http://www.lighttpd.net/2014/3/12/1.4.35/
http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2014_01.txt
http://jvn.jp/en/jp/JVN37417423/index.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00023.html
http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00006.html
http://marc.info/?l=bugtraq&m=141576815022399&w=2
http://seclists.org/oss-sec/2014/q1/561
http://seclists.org/oss-sec/2014/q1/564
http://secunia.com/advisories/57404
http://secunia.com/advisories/57514
http://www.debian.org/security/2014/dsa-2877
http://www.lighttpd.net/2014/3/12/1.4.35/
Products affected by CVE-2014-2323
Lighttpd
»
Lighttpd
»
Version:
1.3.11
cpe:2.3:a:lighttpd:lighttpd:1.3.11
Lighttpd
»
Lighttpd
»
Version:
1.3.12
cpe:2.3:a:lighttpd:lighttpd:1.3.12
Lighttpd
»
Lighttpd
»
Version:
1.3.13
cpe:2.3:a:lighttpd:lighttpd:1.3.13
Lighttpd
»
Lighttpd
»
Version:
1.3.14
cpe:2.3:a:lighttpd:lighttpd:1.3.14
Lighttpd
»
Lighttpd
»
Version:
1.3.15
cpe:2.3:a:lighttpd:lighttpd:1.3.15
Lighttpd
»
Lighttpd
»
Version:
1.3.16
cpe:2.3:a:lighttpd:lighttpd:1.3.16
Lighttpd
»
Lighttpd
»
Version:
1.4.1
cpe:2.3:a:lighttpd:lighttpd:1.4.1
Lighttpd
»
Lighttpd
»
Version:
1.4.10
cpe:2.3:a:lighttpd:lighttpd:1.4.10
Lighttpd
»
Lighttpd
»
Version:
1.4.11
cpe:2.3:a:lighttpd:lighttpd:1.4.11
Lighttpd
»
Lighttpd
»
Version:
1.4.12
cpe:2.3:a:lighttpd:lighttpd:1.4.12
Lighttpd
»
Lighttpd
»
Version:
1.4.13
cpe:2.3:a:lighttpd:lighttpd:1.4.13
Lighttpd
»
Lighttpd
»
Version:
1.4.14
cpe:2.3:a:lighttpd:lighttpd:1.4.14
Lighttpd
»
Lighttpd
»
Version:
1.4.15
cpe:2.3:a:lighttpd:lighttpd:1.4.15
Lighttpd
»
Lighttpd
»
Version:
1.4.16
cpe:2.3:a:lighttpd:lighttpd:1.4.16
Lighttpd
»
Lighttpd
»
Version:
1.4.17
cpe:2.3:a:lighttpd:lighttpd:1.4.17
Lighttpd
»
Lighttpd
»
Version:
1.4.18
cpe:2.3:a:lighttpd:lighttpd:1.4.18
Lighttpd
»
Lighttpd
»
Version:
1.4.19
cpe:2.3:a:lighttpd:lighttpd:1.4.19
Lighttpd
»
Lighttpd
»
Version:
1.4.2
cpe:2.3:a:lighttpd:lighttpd:1.4.2
Lighttpd
»
Lighttpd
»
Version:
1.4.20
cpe:2.3:a:lighttpd:lighttpd:1.4.20
Lighttpd
»
Lighttpd
»
Version:
1.4.21
cpe:2.3:a:lighttpd:lighttpd:1.4.21
Lighttpd
»
Lighttpd
»
Version:
1.4.22
cpe:2.3:a:lighttpd:lighttpd:1.4.22
Lighttpd
»
Lighttpd
»
Version:
1.4.23
cpe:2.3:a:lighttpd:lighttpd:1.4.23
Lighttpd
»
Lighttpd
»
Version:
1.4.24
cpe:2.3:a:lighttpd:lighttpd:1.4.24
Lighttpd
»
Lighttpd
»
Version:
1.4.25
cpe:2.3:a:lighttpd:lighttpd:1.4.25
Lighttpd
»
Lighttpd
»
Version:
1.4.26
cpe:2.3:a:lighttpd:lighttpd:1.4.26
Lighttpd
»
Lighttpd
»
Version:
1.4.27
cpe:2.3:a:lighttpd:lighttpd:1.4.27
Lighttpd
»
Lighttpd
»
Version:
1.4.28
cpe:2.3:a:lighttpd:lighttpd:1.4.28
Lighttpd
»
Lighttpd
»
Version:
1.4.29
cpe:2.3:a:lighttpd:lighttpd:1.4.29
Lighttpd
»
Lighttpd
»
Version:
1.4.3
cpe:2.3:a:lighttpd:lighttpd:1.4.3
Lighttpd
»
Lighttpd
»
Version:
1.4.30
cpe:2.3:a:lighttpd:lighttpd:1.4.30
Lighttpd
»
Lighttpd
»
Version:
1.4.31
cpe:2.3:a:lighttpd:lighttpd:1.4.31
Lighttpd
»
Lighttpd
»
Version:
1.4.32
cpe:2.3:a:lighttpd:lighttpd:1.4.32
Lighttpd
»
Lighttpd
»
Version:
1.4.33
cpe:2.3:a:lighttpd:lighttpd:1.4.33
Lighttpd
»
Lighttpd
»
Version:
1.4.34
cpe:2.3:a:lighttpd:lighttpd:1.4.34
Lighttpd
»
Lighttpd
»
Version:
1.4.4
cpe:2.3:a:lighttpd:lighttpd:1.4.4
Lighttpd
»
Lighttpd
»
Version:
1.4.5
cpe:2.3:a:lighttpd:lighttpd:1.4.5
Lighttpd
»
Lighttpd
»
Version:
1.4.6
cpe:2.3:a:lighttpd:lighttpd:1.4.6
Lighttpd
»
Lighttpd
»
Version:
1.4.7
cpe:2.3:a:lighttpd:lighttpd:1.4.7
Lighttpd
»
Lighttpd
»
Version:
1.4.8
cpe:2.3:a:lighttpd:lighttpd:1.4.8
Lighttpd
»
Lighttpd
»
Version:
1.4.9
cpe:2.3:a:lighttpd:lighttpd:1.4.9
Debian
»
Debian Linux
»
Version:
6.0
cpe:2.3:o:debian:debian_linux:6.0
Debian
»
Debian Linux
»
Version:
7.0
cpe:2.3:o:debian:debian_linux:7.0
Debian
»
Debian Linux
»
Version:
8.0
cpe:2.3:o:debian:debian_linux:8.0
Opensuse
»
Opensuse
»
Version:
11.4
cpe:2.3:o:opensuse:opensuse:11.4
Opensuse
»
Opensuse
»
Version:
12.3
cpe:2.3:o:opensuse:opensuse:12.3
Opensuse
»
Opensuse
»
Version:
13.1
cpe:2.3:o:opensuse:opensuse:13.1
Suse
»
Linux Enterprise High Availability Extension
»
Version:
11
cpe:2.3:o:suse:linux_enterprise_high_availability_extension:11
Suse
»
Linux Enterprise Software Development Kit
»
Version:
11
cpe:2.3:o:suse:linux_enterprise_software_development_kit:11
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved