CVE-2008-4360 — Sensitive Information Exposure in Lighttpd
Severity
7.5HIGHNVD
EPSS
1.0%
top 22.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 3
Latest updateMay 2
Description
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages3 packages
Also affects: Debian Linux 4.0
Patches
🔴Vulnerability Details
2📋Vendor Advisories
2💬Community
5Bugzilla▶
CVE-2008-4360 lighttpd: mod_userdir information disclosure on case-insensitve filesystems↗2008-10-06
Bugzilla
▶
Bugzilla
▶
Bugzilla
▶
Bugzilla
▶