2.6
CVSSv2

CVE-2006-0760

Published: 18/02/2006 Updated: 20/07/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

LightTPD 1.4.8 and previous versions, when the web root is on a case-insensitive filesystem, allows remote malicious users to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for ".php" names.

Vulnerable Product Search on Vulmon Subscribe to Product

lighttpd lighttpd 1.1.4

lighttpd lighttpd 1.1.5

lighttpd lighttpd 1.2.3

lighttpd lighttpd 1.2.4

lighttpd lighttpd 1.3.10

lighttpd lighttpd 1.3.11

lighttpd lighttpd 1.3.3

lighttpd lighttpd 1.3.4

lighttpd lighttpd 1.4.2

lighttpd lighttpd 1.4.3

lighttpd lighttpd 1.0.2

lighttpd lighttpd 1.0.3

lighttpd lighttpd 1.1.6

lighttpd lighttpd 1.1.7

lighttpd lighttpd 1.2.5

lighttpd lighttpd 1.2.6

lighttpd lighttpd 1.3.12

lighttpd lighttpd 1.3.13

lighttpd lighttpd 1.3.5

lighttpd lighttpd 1.3.6

lighttpd lighttpd 1.4.4

lighttpd lighttpd 1.4.5

lighttpd lighttpd 1.1.2

lighttpd lighttpd 1.1.3

lighttpd lighttpd 1.2.0

lighttpd lighttpd 1.2.1

lighttpd lighttpd 1.2.2

lighttpd lighttpd 1.3.0

lighttpd lighttpd 1.3.1

lighttpd lighttpd 1.3.16

lighttpd lighttpd 1.3.2

lighttpd lighttpd 1.4.0

lighttpd lighttpd 1.4.1

lighttpd lighttpd 1.4.8

lighttpd lighttpd 1.1.0

lighttpd lighttpd 1.1.1

lighttpd lighttpd 1.1.8

lighttpd lighttpd 1.1.9

lighttpd lighttpd 1.2.7

lighttpd lighttpd 1.2.8

lighttpd lighttpd 1.3.14

lighttpd lighttpd 1.3.15

lighttpd lighttpd 1.3.7

lighttpd lighttpd 1.3.8

lighttpd lighttpd 1.3.9

lighttpd lighttpd 1.4.6

lighttpd lighttpd 1.4.7