Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown

CVE-2002-2103

Disclosure Date: December 31, 2002 (last updated October 03, 2023)
Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
0
Attacker Value
Unknown

CVE-2002-2029

Disclosure Date: December 31, 2002 (last updated October 03, 2023)
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
0
Attacker Value
Unknown

CVE-2002-1233

Disclosure Date: November 04, 2002 (last updated October 03, 2023)
A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
0
Attacker Value
Unknown

CVE-2002-0843

Disclosure Date: October 11, 2002 (last updated October 03, 2023)
Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
0
Attacker Value
Unknown

CVE-2002-0840

Disclosure Date: October 11, 2002 (last updated October 03, 2023)
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
0
Attacker Value
Unknown

CVE-2002-0257

Disclosure Date: May 29, 2002 (last updated October 03, 2023)
Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4.
0
Attacker Value
Unknown

CVE-2001-0730

Disclosure Date: October 30, 2001 (last updated October 03, 2023)
split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.
0
Attacker Value
Unknown

CVE-2001-0729

Disclosure Date: October 30, 2001 (last updated October 03, 2023)
Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.
0
Attacker Value
Unknown

CVE-2001-0731

Disclosure Date: October 01, 2001 (last updated October 03, 2023)
Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.
0