Description
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.
Remediation
References
Related Vulnerabilities
Liferay DXP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2025-62258)
WordPress Plugin Use Any Font Unspecified Vulnerability (4.3.6)
WordPress Plugin wp superb Slideshow 'upload.php' Arbitrary File Upload (2.2)
MySQL CVE-2024-21200 Vulnerability (CVE-2024-21200)
WordPress Plugin GD Rating System Multiple Vulnerabilities (2.3)