Description
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
Remediation
References
Related Vulnerabilities
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2007-6752)
Moodle Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-6970)
Sqlite Use After Free Vulnerability (CVE-2019-5018)
Apache HTTP Server Other Vulnerability (CVE-2010-1452)
WordPress Plugin Product Reviews Import Export for WooCommerce CSV Injection (1.4.8)