Vulnerability record · CVE-2014-2323 · published 14 March 2014
CVE-2014-2323: lighttpd mod_mysql_vhost SQL injection via host name
Lighttpd · Lighttpd
lighttpd before 1.4.35 contains a SQL injection flaw in mod_mysql_vhost.c, specifically in request_check_hostname, where the HTTP host name is passed into SQL without proper sanitization. Because the host header is attacker-controlled and the module uses it to look up virtual host configuration in a database, this exposes the backend database to arbitrary SQL execution.
Description
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 3.1 base score is 9.8 (critical) with network reachability, no privileges and no user interaction, and public exploit references exist.
What it is
lighttpd before 1.4.35 contains a SQL injection flaw in mod_mysql_vhost.c, specifically in request_check_hostname, where the HTTP host name is passed into SQL without proper sanitization. Because the host header is attacker-controlled and the module uses it to look up virtual host configuration in a database, this exposes the backend database to arbitrary SQL execution.
Impact
An unauthenticated remote attacker can execute arbitrary SQL commands against the database backing mod_mysql_vhost, potentially reading, modifying or deleting data and, depending on database privileges, escalating further.
Attack surface
Reached over the network by sending a crafted Host header in an HTTP request to a lighttpd instance that has mod_mysql_vhost enabled; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is high (0.62752, 99.157th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade lighttpd to 1.4.35 or later, which contains the fix referenced in the vendor advisory and patch link.
- If mod_mysql_vhost is not required, disable or remove it to eliminate the attack path.
- Apply the vendor and distribution patches (Debian DSA-2877, openSUSE/SUSE advisories) where upgrading is not immediately possible.
- Restrict the database account used by mod_mysql_vhost to the minimum privileges needed for host lookups.
- Validate or normalize the Host header at a reverse proxy or WAF in front of lighttpd as a compensating control.
Detection
- Inspect HTTP Host headers for SQL metacharacters (quotes, comment sequences, UNION, stacked queries) reaching lighttpd.
- Monitor database logs for anomalous queries or errors originating from the web server host.
- Alert on lighttpd versions below 1.4.35 in asset inventories or banner checks.
- Review mod_mysql_vhost configuration and database account permissions for unexpected changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-2323 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-2323), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.