CVE-2015-3200

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
09/06/2015
Last modified:
12/04/2025

Description

mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lighttpd:lighttpd:*:*:*:*:*:*:*:* 1.4.35 (including)
cpe:2.3:a:hp:virtual_customer_access_system:*:*:*:*:*:*:*:* 15.07 (including)
cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*