CVE-2008-1270
10.03.2008, 21:44
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.Enginsight
| Vendor | Product | Version |
|---|---|---|
| lighttpd | lighttpd | 𝑥 ≤ 1.4.18 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References