SQL injection vulnerability in lighttpd before 1.4.35 when modmysqlvhost is in use, due to insufficient validation of hostnames in HTTP requests (CVE-2014-2323).
Possible path traversal vulnerabilities in lighttpd before 1.4.35 when either modevhost or modsimple_vhost are in use, due to insufficient validation of hostnames in HTTP requests (CVE-2014-2324).