Back
CVE-2014-2323
CRITICAL
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
Published: Mar 14, 2014
Modified: May 6, 2026
CWE-89
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (9)
| Vendor | Product | Version |
|---|---|---|
| lighttpd | lighttpd | * < 1.4.35 |
| debian | debian_linux | 6.0 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| opensuse | opensuse | 11.4 |
| opensuse | opensuse | 12.3 |
| opensuse | opensuse | 13.1 |
| suse | linux_enterprise_high_availability_extension | 11 |
| suse | linux_enterprise_software_development_kit | 11 |
GitHub Security Advisory GHSA-v97w-2rqc-4p78
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote...
References (24)
- http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2014_01.txt Exploit, Vendor Advisory
- http://jvn.jp/en/jp/JVN37417423/index.html Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00023.html Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00002.html Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00006.html Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=141576815022399&w=2 Mailing List, Third Party Advisory
- http://seclists.org/oss-sec/2014/q1/561 Exploit, Mailing List, Third Party Advisory
- http://seclists.org/oss-sec/2014/q1/564 Mailing List, Third Party Advisory
- http://secunia.com/advisories/57404 Broken Link
- http://secunia.com/advisories/57514 Broken Link
- http://www.debian.org/security/2014/dsa-2877 Third Party Advisory
- http://www.lighttpd.net/2014/3/12/1.4.35/ Patch, Vendor Advisory
- http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2014_01.txt Exploit, Vendor Advisory
- http://jvn.jp/en/jp/JVN37417423/index.html Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00023.html Mailing List, Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
91.04%
Top 0% most likely to be exploited
Threat Score
76.5 / 100
Data Sources
NVD
EPSS
GitHub