Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lighttpd 'mod_userdir' 信息泄露漏洞
Vulnerability Description
lighttpd是目前非常流行的开放源代码的web服务器。 当未对userdir.path进行设置时,lighttpd中的mod_userdir使用默认的$HOME,远程攻击者可以读取任意文件,比如访问nobody目录。
CVSS Information
N/A
Vulnerability Type
N/A