CVE-2008-1111: Lighttpd
Medium severity, CVSS 5.0. EPSS: 2% chance of exploitation in the next 30 days.
mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers to obtain sensitive information.
Affected products
- Lighttpd Lighttpd: version 1.4.18 only
Published 2008-03-04. Last modified 2026-06-16.