Loading
The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.
Use Lighttpd vendor hub and Lighttpd product page to widen CVE-2005-0453 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-11072, CVE-2014-2323 and CVE-2013-4559 for nearby disclosures in the same product family.