Description
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt file extension.
Remediation
References
Related Vulnerabilities
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.27)
Joomla Missing Authorization Vulnerability (CVE-2019-18674)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3724)
WordPress Plugin WPS Limit Login Multiple Vulnerabilities (1.4.5)
WordPress Plugin Social Media Widget by Acurax Cross-Site Request Forgery (3.2.5)