lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
Metrics
Affected Vendors & Products
References
History
Thu, 22 May 2025 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T10:17:08.779Z
Reserved: 2008-09-30T00:00:00
Link: CVE-2008-4359

No data.

Status : Deferred
Published: 2008-10-03T17:41:40.430
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-4359
