CVE-2008-1270
10.03.2008, 21:44
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.Enginsight
Vendor | Product | Version |
---|---|---|
lighttpd | lighttpd | 𝑥 ≤ 1.4.18 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References