PT-2006-4951 · Apache · Apache

Susam Pal

·

Published

2006-08-14

·

Updated

2018-10-17

·

CVE-2006-4110

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache version 2.2.2
Description The issue allows remote attackers to read the source code of CGI programs. This is achieved by sending a request that contains uppercase or alternate case characters, which bypasses the case-sensitive ScriptAlias directive. However, on case-insensitive file systems, this allows access to the file.
Recommendations For Apache version 2.2.2, consider modifying the ScriptAlias directive to handle case-insensitive file systems or restrict access to CGI programs until a proper fix is applied. As a temporary workaround, consider disabling CGI programs or restricting access to them to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4110

Affected Products

Apache