CVE-2014-2323 | lighttpd up to 1.4.34 MySQL Virtual Hosting mod_mysql_vhost.c sql injection (Bug 1075703 / Nessus ID 73193)
A vulnerability described as critical has been identified in lighttpd. The affected element is an unknown function of the file mod_mysql_vhost.c of the component MySQL Virtual Hosting Module. The manipulation results in sql injection.
This vulnerability is reported as CVE-2014-2323. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.