PT-2005-1269 · Apache · Mod Dosevasive
Published
2005-01-06
·
Updated
2017-07-11
·
CVE-2005-0182
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
mod dosevasive module for Apache versions 1.9 and earlier
Description
The issue allows remote attackers to overwrite arbitrary files via a symlink attack due to the creation of temporary files with predictable filenames.
Recommendations
For mod dosevasive module for Apache versions 1.9 and earlier, consider updating to a version later than 1.9 to resolve the issue. As a temporary workaround, consider restricting access to the temporary files created by the mod dosevasive module to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mod Dosevasive