response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests that contain trailing (1) "." (dot) and (2) space characters, which are ignored by Windows, as demonstrated by PHP files.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2006-03-06T21:00:00
Updated: 2024-08-07T16:48:56.456Z
Reserved: 2006-02-21T00:00:00
Link: CVE-2006-0814
Vulnrichment
No data.
NVD
Status : Modified
Published: 2006-03-06T21:02:00.000
Modified: 2024-11-21T00:07:24.133
Link: CVE-2006-0814
Redhat
No data.