imPC@ndo IT

Tracker / CVE-2001-1556

CVE-2001-1556

Medium 5.0

The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.

Affected products and versions

apache http_server · 1.3.0 → 1.3.31
apache http_server · 2.0.0 → 2.0.49

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References