CVE-2001-1449
- EPSS 5.43%
- Published 28.11.2001 05:00:00
- Last modified 03.04.2025 01:03:51
The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
- EPSS 2.31%
- Published 30.10.2001 05:00:00
- Last modified 03.04.2025 01:03:51
Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.
- EPSS 7.8%
- Published 30.10.2001 05:00:00
- Last modified 03.04.2025 01:03:51
split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.
CVE-2001-0766
- EPSS 11.23%
- Published 18.10.2001 04:00:00
- Last modified 03.04.2025 01:03:51
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
- EPSS 71.87%
- Published 01.10.2001 04:00:00
- Last modified 03.04.2025 01:03:51
Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.
- EPSS 0.9%
- Published 31.08.2001 04:00:00
- Last modified 03.04.2025 01:03:51
Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
- EPSS 10.15%
- Published 12.05.2001 04:00:00
- Last modified 03.04.2025 01:03:51
Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a n...
CVE-2001-0131
- EPSS 0.11%
- Published 12.03.2001 05:00:00
- Last modified 03.04.2025 01:03:51
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
- EPSS 83.32%
- Published 12.03.2001 05:00:00
- Last modified 03.04.2025 01:03:51
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1...
- EPSS 22.55%
- Published 16.02.2001 05:00:00
- Last modified 03.04.2025 01:03:51
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.