S4E just found a critical-severity finding from cve-2024-42009 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2014-2323 Scanner

Detects 'SQL Injection' vulnerability in lighttpd affects v. before 1.4.35.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
3.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2014-2323
9.8
CVSS

SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Lighttpd is a popular web server software designed for high-performance environments. It is known for its speed and scalability, making it a popular choice for a variety of web applications. This software is often used in load balancing and content delivery networks. Lighttpd is open-source, which means that it is freely available and can be customized to suit the unique needs of each user. It offers a range of features such as mod_rewrite, mod_fastcgi, and mod_accesslog that makes it easy for users to customize the configuration of their server.

CVE-2014-2323 is a vulnerability that was detected in Lighttpd before version 1.4.35. This vulnerability is caused by an SQL injection vulnerability in mod_mysql_vhost.c. It allows attackers to execute arbitrary SQL commands via the hostname, related to request_check_hostname. An attacker could exploit this vulnerability by manipulating the hostname to inject malicious SQL commands into the server. This could lead to data loss, data theft, and unauthorized access to sensitive information.

When this vulnerability is exploited, it can lead to serious consequences for the affected system. Attackers can use the vulnerability to gain unauthorized access to sensitive information, execute malicious commands on the server, and even steal data. An attacker can take control of the system, inject commands, and steal valuable data.

s4e.io offers pro features that make it easy for users to quickly and easily learn about vulnerabilities in their digital assets. Users can use the platform to get real-time updates on vulnerabilities, monitor their assets, and get actionable insights to protect their systems. With the pro features of s4e.io, users can access a robust dashboard, alerts, and other features that help them stay ahead of emerging threats.

 

REFERENCES

Solution Advice

Precautions can be taken to protect against this vulnerability. These include:

  • Upgrading to the latest version of Lighttpd (1.4.35 or higher)
  • Restricting access to the server
  • Implementing access controls
  • Disabling any unnecessary modules or plugins
  • Using secure coding practices for web applications

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2014-2323 scanner - SQL Injection vulnerability in lighttpd | S4E