CVE-2007-3949
EPSS 0.61%發布日:2007/7/24修改日:2026/4/28
描述
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.
受影響套件(1)
- Debian/lighttpdfrom 0, < 1.4.16-1
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.