Description
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
Remediation
References
Related Vulnerabilities
ATutor Improper Privilege Management Vulnerability (CVE-2017-1000003)
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.35)
WordPress Plugin WordPress Popular Posts TimThumb Arbitrary File Upload (2.1.4)
MySQL CVE-2024-21142 Vulnerability (CVE-2024-21142)
WordPress Plugin WP-Cumulus 'tagcloud.swf' Cross-Site Scripting (1.22)