Description
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Mailto Links-Manage Email Links Cross-Site Scripting (2.0.1)
MySQL CVE-2016-0601 Vulnerability (CVE-2016-0601)
MySQL CVE-2012-1703 Vulnerability (CVE-2012-1703)
WordPress Plugin WP-UserOnline Cross-Site Scripting (2.88.0)
Oracle Database Server CVE-2011-0804 Vulnerability (CVE-2011-0804)