Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-47903 1 Litespeed Technologies 1 Litespeed Web Server 2026-01-26 8.8 High
LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash command injection.
CVE-2007-5654 1 Litespeed Technologies 1 Litespeed Web Server 2025-04-09 N/A
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime Type Injection."
CVE-2005-3695 1 Litespeed Technologies 1 Litespeed Web Server 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the m parameter.