- EPSS 8.16%
- Published 19.12.2000 05:00:00
- Last modified 03.04.2025 01:03:51
mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
- EPSS 8.81%
- Published 14.11.2000 05:00:00
- Last modified 03.04.2025 01:03:51
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
- EPSS 10.57%
- Published 14.11.2000 05:00:00
- Last modified 03.04.2025 01:03:51
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
- EPSS 4.86%
- Published 13.10.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.
- EPSS 46.37%
- Published 31.05.2000 04:00:00
- Last modified 03.04.2025 01:03:51
The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
CVE-2000-1205
- EPSS 4.28%
- Published 01.02.2000 05:00:00
- Last modified 03.04.2025 01:03:51
Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error...
- EPSS 1.34%
- Published 31.12.1999 05:00:00
- Last modified 03.04.2025 01:03:51
mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.
- EPSS 1.29%
- Published 12.12.1999 05:00:00
- Last modified 03.04.2025 01:03:51
The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.
CVE-1999-1053
- EPSS 88.55%
- Published 13.09.1999 04:00:00
- Last modified 03.04.2025 01:03:51
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allo...
- EPSS 5.02%
- Published 03.09.1999 04:00:00
- Last modified 03.04.2025 01:03:51
Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.