4.9

CVE-2009-1195

Exploit

The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.

Data is provided by the National Vulnerability Database (NVD)
ApacheHTTP Server Version2.2.0
ApacheHTTP Server Version2.2.1
ApacheHTTP Server Version2.2.2
ApacheHTTP Server Version2.2.3
ApacheHTTP Server Version2.2.4
ApacheHTTP Server Version2.2.7
ApacheHTTP Server Version2.2.8
ApacheHTTP Server Version2.2.9
ApacheHTTP Server Version2.2.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.22% 0.443
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
http://secunia.com/advisories/35264
Third Party Advisory
Vendor Advisory
http://www.securityfocus.com/bid/35115
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1022296
Third Party Advisory
VDB Entry