PT-2000-1825 · Apache · Apache+1
Published
2000-09-29
·
Updated
2021-06-06
·
CVE-2000-0913
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache versions 1.3.12 and earlier
Description
The issue allows remote attackers to read arbitrary files on the web server under specific conditions. This occurs when the RewriteRule directive in the mod rewrite module is expanded to include a filename containing a regular expression, enabling access to any file on the server.
Recommendations
For Apache versions 1.3.12 and earlier, consider disabling the mod rewrite module or restricting its use to minimize the risk of exploitation until a fix is available. As a temporary workaround, review and modify RewriteRule directives to avoid using regular expression references in the destination, thereby preventing unauthorized file access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache
Apache Http Server