PT-2000-1825 · Apache · Apache+1

Published

2000-09-29

·

Updated

2021-06-06

·

CVE-2000-0913

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache versions 1.3.12 and earlier
Description The issue allows remote attackers to read arbitrary files on the web server under specific conditions. This occurs when the RewriteRule directive in the mod rewrite module is expanded to include a filename containing a regular expression, enabling access to any file on the server.
Recommendations For Apache versions 1.3.12 and earlier, consider disabling the mod rewrite module or restricting its use to minimize the risk of exploitation until a fix is available. As a temporary workaround, review and modify RewriteRule directives to avoid using regular expression references in the destination, thereby preventing unauthorized file access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0913

Affected Products

Apache
Apache Http Server