Information Disclosure Vulnerability in Lighttpd by Lighttpd Foundation
CVE-2008-1270

Currently unrated

Key Information:

Vendor

Lighttpd

Status
Vendor
CVE Published:
10 March 2008

What is CVE-2008-1270?

The mod_userdir feature in Lighttpd versions up to 1.4.18 is vulnerable to information disclosure. When the userdir.path is not explicitly set, it defaults to the user's home directory ($HOME). This misconfiguration allows remote attackers to potentially access sensitive files by exploiting the service, as demonstrated by accessing the default directory of the 'nobody' user, leading to unauthorized data exposure.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.