CVE-2008-1111: Lighttpd

Medium severity, CVSS 5.0. EPSS: 2% chance of exploitation in the next 30 days.

mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers to obtain sensitive information.

Affected products

Published 2008-03-04. Last modified 2026-06-16.