Loading
mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers to obtain sensitive information.
Use CWE-200, Lighttpd vendor hub and Lighttpd product page to widen CVE-2008-1111 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-11072, CVE-2014-2323 and CVE-2013-4559 for nearby disclosures in the same product family.