PT-2001-1912 · Apache · Apache+1
Published
2001-09-28
·
Updated
2021-06-06
·
CVE-2001-0730
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache version 1.3.20
Description:
A issue exists in the split-logfile support program, allowing remote attackers to overwrite arbitrary files with a .log extension via an HTTP request with a specially crafted
Host: header, potentially enabling the writing of any file with a .log extension on the system.Recommendations:
For Apache version 1.3.20, as a temporary workaround, consider restricting access to the split-logfile support program until a patch is available. Avoid using the
Host: header with a slash in HTTP requests to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache
Apache Http Server