Unrated severityNVD Advisory· Published Mar 6, 2006· Updated Jun 16, 2026
CVE-2006-0814
CVE-2006-0814
Description
response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests that contain trailing (1) "." (dot) and (2) space characters, which are ignored by Windows, as demonstrated by PHP files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
50cpe:2.3:a:lighttpd:lighttpd:1.0.2:*:*:*:*:*:*:*+ 49 more
- cpe:2.3:a:lighttpd:lighttpd:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.10:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.11:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.12:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.13:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.14:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.15:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.16:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.7:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.8:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.3.9:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.4.10:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.4.6:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.4.7:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.4.8:*:*:*:*:*:*:*
- cpe:2.3:a:lighttpd:lighttpd:1.4.9:*:*:*:*:*:*:*
- (no CPE)range: <=1.4.10
Patches
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
10- secunia.com/advisories/18886nvdPatchVendor Advisory
- secunia.com/secunia_research/2006-9/advisory/nvdPatchVendor Advisory
- securityreason.com/securityalert/523nvd
- securitytracker.com/idnvd
- trac.lighttpd.net/trac/changeset/1005nvd
- www.osvdb.org/23542nvd
- www.securityfocus.com/archive/1/426446/100/0/threadednvd
- www.securityfocus.com/bid/16893nvd
- www.vupen.com/english/advisories/2006/0782nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24976nvd
News mentions
0No linked articles in our index yet.