CVE-2008-1270 describes an information disclosure vulnerability in mod_userdir within lighttpd versions 1.4.18 and earlier. When the userdir.path setting is undefined, the server defaults to $HOME, potentially allowing remote attackers to read arbitrary files, such as the ~nobody directory. This vulnerability has a CVSS score of 5.0, indicating a medium severity, with low attack complexity and no authentication required, leading to potential confidentiality impact. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-31396) confirms the existence of public exploit code, and the CVE has garnered significant community discussion, despite no reported active exploitation or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.18CPE matchmatch criteria | cpe:2.3:a:lighttpd:lighttpd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.