Vulnerabilities > Apache > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2002-12-31 | CVE-2002-2103 | Unspecified vulnerability in Apache Http Server Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities. | 5.0 |
2002-12-31 | CVE-2002-2012 | Unspecified vulnerability in Apache Http Server 1.3.19 Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request. | 5.0 |
2002-12-31 | CVE-2002-2007 | Information Disclosure vulnerability in Apache Tomcat 3.2.3/3.2.4 The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages. | 5.0 |
2002-12-31 | CVE-2002-1658 | Buffer Overflow vulnerability in Multiple Apache HTDigest Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. | 4.6 |
2002-05-29 | CVE-2002-0249 | Path Disclosure vulnerability in Apache Http Server 2.0.28 PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message. | 5.0 |
2002-05-29 | CVE-2002-0240 | Path Disclosure vulnerability in Apache Http Server 2.0.28 PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message. | 5.0 |
2002-03-22 | CVE-2000-1210 | Directory Traversal vulnerability in Apache Tomcat 1.1.3/3.0/3.1 Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. | 5.0 |
2001-12-31 | CVE-2001-1556 | Remote Security vulnerability in Apache The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep. | 5.0 |
2001-12-06 | CVE-2001-0829 | Cross-Site Scripting vulnerability in Apache Tomcat 3.2.1 A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message. | 5.1 |
2001-08-31 | CVE-2001-1072 | Unspecified vulnerability in Apache Http Server 1.3.14/1.3.17/1.3.19 Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail. | 5.0 |