Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

CVE-2022-30780 - lighttpd remote denial of service

NotificationsYou must be signed in to change notification settings

p0dalirius/CVE-2022-30780-lighttpd-denial-of-service

Repository files navigation

CVE-2022-30780 - lighttpd remote denial of service
GitHub release (latest by date)YouTube Channel Subscribers

Summary

An unauthenticated attacker can send an HTTP request with an URL overflowing the maximum URL length, resulting in a denial of service.

Vulnerable versions

The following versions of lighttpd are vulnerable:

SoftwareVersionVulnerable
Lighttpd1.4.58Yes ✅
Lighttpd1.4.57Yes ✅
Lighttpd1.4.56Yes ✅

Usage

$ ./CVE-2022-30780-lighttpd-denial-of-service.py -husage: CVE-2022-30780-lighttpd-denial-of-service.py [-h] [-v] -u URL [-k] [-t THREADS]CVE-2022-30780-lighttpd-denial-of-serviceoptional arguments:  -h, --help            show this help message and exit  -v, --verbose         Verbose mode  -u URL, --url URL     URL to connect to.  -k, --insecure        Allow insecure server connections when using SSL (default: False)  -t THREADS, --threads THREADS                        Number of threads (default: 20)

Demonstration

demo.mp4

References


[8]ページ先頭

©2009-2025 Movatter.jp