Page 29 of 291 results (0.012 seconds)

CVSS: 9.8EPSS: 96%CPEs: 2EXPL: 5

13 Sep 1999 — guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->". • https://www.exploit-db.com/exploits/16914 •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 2

03 Sep 1999 — Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. • https://www.exploit-db.com/exploits/20272 •

CVSS: 7.5EPSS: 1%CPEs: 2EXPL: 0

20 Aug 1999 — Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files. • http://www.apacheweek.com/issues/00-01-07#status •

CVSS: 10.0EPSS: 2%CPEs: 1EXPL: 0

07 Aug 1998 — Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability. • http://marc.info/?l=bugtraq&m=90252779826784&w=2 •

CVSS: 7.5EPSS: 0%CPEs: 9EXPL: 1

30 Dec 1997 — Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters. • https://www.exploit-db.com/exploits/20558 •

CVSS: 10.0EPSS: 0%CPEs: 2EXPL: 0

19 Sep 1997 — Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file. • http://marc.info/?l=bugtraq&m=87602880019796&w=2 •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

01 Sep 1997 — Apache httpd cookie buffer overflow for versions 1.1.1 and earlier. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0071 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

23 Jul 1997 — Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request. • http://marc.info/?l=bugtraq&m=87602661419366&w=2 •

CVSS: 9.1EPSS: 0%CPEs: 11EXPL: 1

10 Dec 1996 — List of arbitrary files on Web host via nph-test-cgi script. • https://www.exploit-db.com/exploits/19536 •

CVSS: 9.1EPSS: 8%CPEs: 1EXPL: 1

01 Apr 1996 — test-cgi program allows an attacker to list files on the server. • https://www.exploit-db.com/exploits/20435 •