vendor:
Web Server
by:
Kingcope
7,5
CVSS
HIGH
Remote Source Code Disclosure
200
CWE
Product Name: Web Server
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2010
Litespeed Technologies Web Server Remote Poison null byte Zero-Day
LiteSpeed Technologies Web Server Remote Source Code Disclosure zero-day Exploit discovered and exploited by Kingcope in June 2010. The exploit allows an attacker to remotely access the source code of a file on the server. The exploit works by sending a specially crafted HTTP request with a null byte at the end of the file name. The server then responds with the source code of the requested file.
Mitigation:
Disable directory listing, use strong passwords, and ensure that all web applications are up to date.