PT-1999-1893 · Apache · Apache Httpd+1
Publicado
1999-08-20
·
Atualizado
2021-06-06
·
CVE-2000-1206
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache httpd versions prior to 1.3.11
Apache httpd version 1.3.9
Description
A security issue exists in Apache httpd, particularly for sites using mass name-based virtual hosting with mod vhost alias or with special mod rewrite rules, allowing remote attackers to retrieve arbitrary files.
Recommendations
For Apache httpd versions prior to 1.3.11, update to version 1.3.11 or later to resolve the issue.
For Apache httpd version 1.3.9, consider disabling the mod vhost alias module or restricting its use until a patch is available.
As a temporary workaround, consider restricting access to mod rewrite rules to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Http Server
Apache Httpd