← Vulnerability feed

Vulnerability record · CVE-2010-2333 · published 18 June 2010

CVE-2010-2333: LiteSpeed Web Server null byte source disclosure

Litespeedtech · Litespeed Web Server

LiteSpeed Web Server 4.0.x before 4.0.15 mishandles HTTP requests that append a null byte followed by a .txt extension, allowing the server to return the source code of scripts instead of executing them. This exposes application source, which can reveal credentials, business logic and further attack paths.

5.0 CVSS 2.0 Medium EPSS 60% · top 0.9% CWE-200 · Information exposure
5.0CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt file extension.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote source disclosure with public exploit code and very high EPSS, though the CVSS base score is only medium and KEV does not list it.

What it is

LiteSpeed Web Server 4.0.x before 4.0.15 mishandles HTTP requests that append a null byte followed by a .txt extension, allowing the server to return the source code of scripts instead of executing them. This exposes application source, which can reveal credentials, business logic and further attack paths.

Impact

An unauthenticated attacker can read the source code of server-side scripts, potentially exposing secrets, configuration details and logic useful for follow-on attacks.

Attack surface

Reachable remotely over HTTP by sending a crafted request with a null byte and .txt extension; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.

Exploitation

Public exploit code is referenced (Exploit-DB, Full Disclosure) and EPSS is high at 0.60196 (99th percentile), but the CVE is not listed in CISA KEV.

What to do

  • Upgrade LiteSpeed Web Server to 4.0.15 or later, which the vendor advisory marks as the patch release.
  • If immediate upgrade is not possible, restrict or filter requests containing null bytes or suspicious .txt suffixes at the web server or WAF layer.
  • Review script and configuration files for hardcoded credentials or secrets that would be exposed if source disclosure occurs.
  • Rotate any credentials or keys that may have been stored in scripts reachable by the affected server.

Detection

  • Search web server access logs for requests containing null bytes (%00) or script paths ending in .txt.
  • Alert on HTTP responses that return source code content types or script source for files that should execute.
  • Monitor for repeated requests to the same script with appended .txt extensions from a single source.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-2333 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2026-31386Litespeedtech litespeed web server os command injection vulnerabilityOpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be ex…EPSS 2.1%7.5CVE-2025-54939Litespeedtech litespeed web adc allocation without limits vulnerabilityLiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.EPSS 0.81%5.0CVE-2004-0112Cisco firewall services module out-of-bounds read vulnerabilityThe SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos …EPSS 10%4.3CVE-2012-4871Litespeedtech litespeed web server cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers …EPSS 1.6%5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed7.5CVE-2026-20133Cisco Catalyst SD-WAN Manager insufficient file system restrictions expose dataCisco Catalyst SD-WAN Software has insufficient file system restrictions that let an attacker read sensitive files on the underlying operating system…KEVEPSS 32%analysed7.5CVE-2025-31125Vite dev server improper access control exposes arbitrary filesVite's dev server fails to restrict file access when a request uses the ?inline&import or ?raw?import query patterns, allowing content of files that …KEVEPSS 65%analysed5.5CVE-2026-20805Windows Desktop Window Manager information disclosureDesktop Windows Manager (DWM) in Microsoft Windows exposes sensitive information to an unauthorized actor, allowing a local attacker with existing ac…KEVEPSS 7.2%analysed

Source: NIST National Vulnerability Database (record CVE-2010-2333), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.