Page 9 of 103 results (0.009 seconds)

CVSS: 7.5EPSS: 3%CPEs: 1EXPL: 2

04 Apr 2001 — Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request. • https://www.exploit-db.com/exploits/20657 •

CVSS: 7.5EPSS: 5%CPEs: 2EXPL: 2

13 Mar 2001 — Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error. • https://www.exploit-db.com/exploits/20531 •

CVSS: 5.3EPSS: 85%CPEs: 5EXPL: 6

12 Mar 2001 — The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex. • https://www.exploit-db.com/exploits/20692 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.5EPSS: 21%CPEs: 1EXPL: 3

16 Feb 2001 — PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences. • https://www.exploit-db.com/exploits/20466 •

CVSS: 5.5EPSS: 0%CPEs: 3EXPL: 0

14 Feb 2001 — htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack. • http://marc.info/?l=bugtraq&m=97916374410647&w=2 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 9.8EPSS: 3%CPEs: 1EXPL: 0

19 Dec 2000 — IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request. • http://marc.info/?l=bugtraq&m=97502498610979&w=2 •

CVSS: 7.5EPSS: 10%CPEs: 10EXPL: 0

19 Dec 2000 — mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression. • http://archives.neohapsis.com/archives/bugtraq/2000-09/0352.html •

CVSS: 7.5EPSS: 10%CPEs: 3EXPL: 0

14 Nov 2000 — The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/. • http://archives.neohapsis.com/archives/linux/suse/2000-q3/0906.html •

CVSS: 9.1EPSS: 7%CPEs: 12EXPL: 2

14 Nov 2000 — The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method. • https://www.exploit-db.com/exploits/20210 •

CVSS: 9.1EPSS: 2%CPEs: 3EXPL: 1

13 Oct 2000 — Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root. • http://www.apacheweek.com/issues/00-10-13 •