Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown
CVE-2002-2103
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
0
Attacker Value
Unknown
CVE-2002-2029
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
0
Attacker Value
Unknown
CVE-2002-0843
Disclosure Date: October 11, 2002 (last updated February 22, 2025)
Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
0
Attacker Value
Unknown
CVE-2002-0840
Disclosure Date: October 11, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
0
Attacker Value
Unknown
CVE-2001-1449
Disclosure Date: November 28, 2001 (last updated February 22, 2025)
The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
0
Attacker Value
Unknown
CVE-2001-0766
Disclosure Date: October 18, 2001 (last updated February 22, 2025)
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
0
Attacker Value
Unknown
CVE-2001-1072
Disclosure Date: August 31, 2001 (last updated February 22, 2025)
Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
0
Attacker Value
Unknown
CVE-2001-1342
Disclosure Date: May 12, 2001 (last updated February 22, 2025)
Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
0
Attacker Value
Unknown
CVE-2001-0925
Disclosure Date: March 12, 2001 (last updated February 22, 2025)
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
0
Attacker Value
Unknown
CVE-2001-0131
Disclosure Date: March 12, 2001 (last updated February 22, 2025)
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
0