Vulnerability record · CVE-2010-2333 · published 18 June 2010
CVE-2010-2333: LiteSpeed Web Server null byte source disclosure
Litespeedtech · Litespeed Web Server
LiteSpeed Web Server 4.0.x before 4.0.15 mishandles HTTP requests that append a null byte followed by a .txt extension, allowing the server to return the source code of scripts instead of executing them. This exposes application source, which can reveal credentials, business logic and further attack paths.
Description
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt file extension.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityUnauthenticated remote source disclosure with public exploit code and very high EPSS, though the CVSS base score is only medium and KEV does not list it.
What it is
LiteSpeed Web Server 4.0.x before 4.0.15 mishandles HTTP requests that append a null byte followed by a .txt extension, allowing the server to return the source code of scripts instead of executing them. This exposes application source, which can reveal credentials, business logic and further attack paths.
Impact
An unauthenticated attacker can read the source code of server-side scripts, potentially exposing secrets, configuration details and logic useful for follow-on attacks.
Attack surface
Reachable remotely over HTTP by sending a crafted request with a null byte and .txt extension; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
Public exploit code is referenced (Exploit-DB, Full Disclosure) and EPSS is high at 0.60196 (99th percentile), but the CVE is not listed in CISA KEV.
What to do
- Upgrade LiteSpeed Web Server to 4.0.15 or later, which the vendor advisory marks as the patch release.
- If immediate upgrade is not possible, restrict or filter requests containing null bytes or suspicious .txt suffixes at the web server or WAF layer.
- Review script and configuration files for hardcoded credentials or secrets that would be exposed if source disclosure occurs.
- Rotate any credentials or keys that may have been stored in scripts reachable by the affected server.
Detection
- Search web server access logs for requests containing null bytes (%00) or script paths ending in .txt.
- Alert on HTTP responses that return source code content types or script source for files that should execute.
- Monitor for repeated requests to the same script with appended .txt extensions from a single source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-2333 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-2333), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.