First published: Fri Oct 03 2008(Updated: )
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fipsasp Fipscms Light | <1.4.20 | |
Debian Linux | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4360 has been classified as a medium severity vulnerability.
To mitigate CVE-2008-4360, upgrade to lighttpd version 1.4.20 or later.
CVE-2008-4360 affects lighttpd versions prior to 1.4.20.
CVE-2008-4360 impacts lighttpd when running on case-insensitive operating systems or filesystems.
Yes, CVE-2008-4360 can allow remote attackers to bypass intended access restrictions.