CVE-2008-1270
lighttpd < 1.4.18 - Unauthenticated Arbitrary File Read via mod_userdir Default Path
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1270. PoCs published by julien.cayzac.
AI-analyzed exploit summary The exploit describes an information disclosure vulnerability in lighttpd 1.4.18 due to improper handling of exceptional conditions, allowing attackers to access sensitive files like /etc/passwd via crafted URLs.
Description
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.
Exploits (1)
The exploit describes an information disclosure vulnerability in lighttpd 1.4.18 due to improper handling of exceptional conditions, allowing attackers to access sensitive files like /etc/passwd via crafted URLs.