Loading
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
Use CWE-89, Lighttpd vendor hub and Lighttpd product page to widen CVE-2014-2323 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-11072, CVE-2013-4559 and CVE-2022-41556 for nearby disclosures in the same product family.