lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T10:17:08.779Z
Reserved: 2008-09-30T00:00:00
Link: CVE-2008-4359

No data.

Status : Modified
Published: 2008-10-03T17:41:40.430
Modified: 2024-11-21T00:51:29.550
Link: CVE-2008-4359
