Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2008-1270 — Sensitive Information Exposure in Lighttpd
Severity
5.0MEDIUMNVD
EPSS
8.8%
top 7.46%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMar 10
Latest updateMay 1
Description
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages3 packages
🔴Vulnerability Details
2💥Exploits & PoCs
1📋Vendor Advisories
6Debian▶
CVE-2008-1270: lighttpd - mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a...↗2008