Record summary

CVE-2012-5533 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBlighttpd 1.4.31 - Denial of Service (PoC)ExploitDB exploitby t4cNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 17