Information Disclosure Vulnerability in Lighttpd by Lighttpd Foundation
CVE-2008-1270
Currently unrated
What is CVE-2008-1270?
The mod_userdir feature in Lighttpd versions up to 1.4.18 is vulnerable to information disclosure. When the userdir.path is not explicitly set, it defaults to the user's home directory ($HOME). This misconfiguration allows remote attackers to potentially access sensitive files by exploiting the service, as demonstrated by accessing the default directory of the 'nobody' user, leading to unauthorized data exposure.