Description
mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.
Remediation
References
Related Vulnerabilities
OpenSSL Integer Overflow or Wraparound Vulnerability (CVE-2016-2177)
WordPress Plugin SRS Simple Hits Counter SQL Injection (1.0.4)
Internet Information Services Other Vulnerability (CVE-2001-0544)
Oracle Database Server CVE-2014-6452 Vulnerability (CVE-2014-6452)
SugarCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-35808)