Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-1270

Опубликовано: 10 мар. 2008
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.

РелизСтатусПримечание
dapper

released

1.4.11-3ubuntu3.8
devel

released

1.4.18-1ubuntu6
edgy

released

1.4.13~r1370-1ubuntu1.6
feisty

released

1.4.13-9ubuntu4.5
gutsy

released

1.4.18-1ubuntu1.3
upstream

needed

Показывать по

Ссылки на источники

EPSS

Процентиль: 91%
0.06276
Низкий

5 Medium

CVSS2

Связанные уязвимости

nvd
больше 17 лет назад

mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.

debian
больше 17 лет назад

mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not s ...

github
больше 3 лет назад

mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.

EPSS

Процентиль: 91%
0.06276
Низкий

5 Medium

CVSS2