← back
CVE-2014-2323

CVE-2014-2323

30Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 62%
exploitation probability
62%top 1% of all CVEs
observed exploitation
nono source reports it
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
Affected products
n/a · n/a