CVE Vulnerabilities

CVE-2006-0760

Published: Feb 18, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for .php names.

Affected Software

Name Vendor Start Version End Version
Lighttpd Lighttpd 1.0.2 (including) 1.0.2 (including)
Lighttpd Lighttpd 1.0.3 (including) 1.0.3 (including)
Lighttpd Lighttpd 1.1.0 (including) 1.1.0 (including)
Lighttpd Lighttpd 1.1.1 (including) 1.1.1 (including)
Lighttpd Lighttpd 1.1.2 (including) 1.1.2 (including)
Lighttpd Lighttpd 1.1.3 (including) 1.1.3 (including)
Lighttpd Lighttpd 1.1.4 (including) 1.1.4 (including)
Lighttpd Lighttpd 1.1.5 (including) 1.1.5 (including)
Lighttpd Lighttpd 1.1.6 (including) 1.1.6 (including)
Lighttpd Lighttpd 1.1.7 (including) 1.1.7 (including)
Lighttpd Lighttpd 1.1.8 (including) 1.1.8 (including)
Lighttpd Lighttpd 1.1.9 (including) 1.1.9 (including)
Lighttpd Lighttpd 1.2.0 (including) 1.2.0 (including)
Lighttpd Lighttpd 1.2.1 (including) 1.2.1 (including)
Lighttpd Lighttpd 1.2.2 (including) 1.2.2 (including)
Lighttpd Lighttpd 1.2.3 (including) 1.2.3 (including)
Lighttpd Lighttpd 1.2.4 (including) 1.2.4 (including)
Lighttpd Lighttpd 1.2.5 (including) 1.2.5 (including)
Lighttpd Lighttpd 1.2.6 (including) 1.2.6 (including)
Lighttpd Lighttpd 1.2.7 (including) 1.2.7 (including)
Lighttpd Lighttpd 1.2.8 (including) 1.2.8 (including)
Lighttpd Lighttpd 1.3.0 (including) 1.3.0 (including)
Lighttpd Lighttpd 1.3.1 (including) 1.3.1 (including)
Lighttpd Lighttpd 1.3.2 (including) 1.3.2 (including)
Lighttpd Lighttpd 1.3.3 (including) 1.3.3 (including)
Lighttpd Lighttpd 1.3.4 (including) 1.3.4 (including)
Lighttpd Lighttpd 1.3.5 (including) 1.3.5 (including)
Lighttpd Lighttpd 1.3.6 (including) 1.3.6 (including)
Lighttpd Lighttpd 1.3.7 (including) 1.3.7 (including)
Lighttpd Lighttpd 1.3.8 (including) 1.3.8 (including)
Lighttpd Lighttpd 1.3.9 (including) 1.3.9 (including)
Lighttpd Lighttpd 1.3.10 (including) 1.3.10 (including)
Lighttpd Lighttpd 1.3.11 (including) 1.3.11 (including)
Lighttpd Lighttpd 1.3.12 (including) 1.3.12 (including)
Lighttpd Lighttpd 1.3.13 (including) 1.3.13 (including)
Lighttpd Lighttpd 1.3.14 (including) 1.3.14 (including)
Lighttpd Lighttpd 1.3.15 (including) 1.3.15 (including)
Lighttpd Lighttpd 1.3.16 (including) 1.3.16 (including)
Lighttpd Lighttpd 1.4.0 (including) 1.4.0 (including)
Lighttpd Lighttpd 1.4.1 (including) 1.4.1 (including)
Lighttpd Lighttpd 1.4.2 (including) 1.4.2 (including)
Lighttpd Lighttpd 1.4.3 (including) 1.4.3 (including)
Lighttpd Lighttpd 1.4.4 (including) 1.4.4 (including)
Lighttpd Lighttpd 1.4.5 (including) 1.4.5 (including)
Lighttpd Lighttpd 1.4.6 (including) 1.4.6 (including)
Lighttpd Lighttpd 1.4.7 (including) 1.4.7 (including)
Lighttpd Lighttpd 1.4.8 (including) 1.4.8 (including)

References