LiteSpeed Web Server – Security Advisory – HTTP Header Injection Vulnerability

Posted by Onur Yilmaz on Jan 20

Information
——————–
Advisory by Netsparker
Name: HTTP Header Injection in LiteSpeed Web Server
Affected Software : LiteSpeed Web Server
Affected Versions: v5.1.0 and possibly below
Vendor Homepage : https://www.litespeedtech.com/
Vulnerability Type : HTTP Header Injection
Severity : Medium
Status : Fixed
CVE-ID : TBA
Netsparker Advisory Reference : NS-16-001

Description
——————–
While testing Netsparker, we spotted an…