Description: A vulnerability has been reported in lighttpd, which can be exploited by malicious people to disclose potentially sensitive information.
The vulnerability is caused due to a validation error of the filename extension supplied by the user in the URL when it contains uppercase characters. This can be exploited to retrieve the source code of PHP or PERL script files from an affected system that uses case-insenstive filesystems (e.g. Windows or HFS on MacOSX).
The vulnerability has been reported in versions 1.4.8 and prior.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.