Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown

CVE-2002-2103

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
0
Attacker Value
Unknown

CVE-2002-2029

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
0
Attacker Value
Unknown

CVE-2002-0843

Disclosure Date: October 11, 2002 (last updated February 22, 2025)
Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
0
Attacker Value
Unknown

CVE-2002-0840

Disclosure Date: October 11, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
0
Attacker Value
Unknown

CVE-2001-1449

Disclosure Date: November 28, 2001 (last updated February 22, 2025)
The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
0
Attacker Value
Unknown

CVE-2001-0925

Disclosure Date: March 12, 2001 (last updated February 22, 2025)
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
0
Attacker Value
Unknown

CVE-2000-0913

Disclosure Date: December 19, 2000 (last updated February 22, 2025)
mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
0
Attacker Value
Unknown

CVE-2000-1204

Disclosure Date: October 13, 2000 (last updated February 22, 2025)
Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.
0
Attacker Value
Unknown

CVE-2000-0505

Disclosure Date: May 31, 2000 (last updated February 22, 2025)
The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
0
Attacker Value
Unknown

CVE-2000-1205

Disclosure Date: February 01, 2000 (last updated February 22, 2025)
Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.
0