CVE-2014-2323

CVE-2014-2323

Published · Updated

30Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 63%
exploitation probability
63%top 1% of all CVEs
observed exploitation
nono source reports it
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
Affected products
n/a · n/a