cve/2007/CVE-2007-5654.md
2024-06-18 02:51:15 +02:00

727 B

CVE-2007-5654

Description

LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime Type Injection."

POC

Reference

Github

No PoCs found on GitHub currently.