Vulnerabilities > Apache > Medium

DATE CVE VULNERABILITY TITLE RISK
2002-12-31 CVE-2002-2103 Unspecified vulnerability in Apache Http Server
Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
network
low complexity
apache
5.0
2002-12-31 CVE-2002-2012 Unspecified vulnerability in Apache Http Server 1.3.19
Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.
network
low complexity
apache
5.0
2002-12-31 CVE-2002-2007 Information Disclosure vulnerability in Apache Tomcat 3.2.3/3.2.4
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
network
low complexity
apache
5.0
2002-12-31 CVE-2002-1658 Buffer Overflow vulnerability in Multiple Apache HTDigest
Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument.
local
low complexity
apache
4.6
2002-05-29 CVE-2002-0249 Path Disclosure vulnerability in Apache Http Server 2.0.28
PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.
network
low complexity
apache
5.0
2002-05-29 CVE-2002-0240 Path Disclosure vulnerability in Apache Http Server 2.0.28
PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.
network
low complexity
apache
5.0
2002-03-22 CVE-2000-1210 Directory Traversal vulnerability in Apache Tomcat 1.1.3/3.0/3.1
Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a ..
network
low complexity
apache
5.0
2001-12-31 CVE-2001-1556 Remote Security vulnerability in Apache
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
network
low complexity
apache
5.0
2001-12-06 CVE-2001-0829 Cross-Site Scripting vulnerability in Apache Tomcat 3.2.1
A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
network
high complexity
apache
5.1
2001-08-31 CVE-2001-1072 Unspecified vulnerability in Apache Http Server 1.3.14/1.3.17/1.3.19
Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
network
low complexity
apache
5.0