Vulnerabilities > Apache > Medium

DATE CVE VULNERABILITY TITLE RISK
2003-02-07 CVE-2003-0044 Cross-Site Scripting vulnerability in Apache Tomcat Example Web Application
Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.
network
apache
6.8
2003-02-07 CVE-2003-0043 Unspecified vulnerability in Apache Tomcat
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.
network
low complexity
apache
5.0
2003-02-07 CVE-2003-0042 Unspecified vulnerability in Apache Tomcat
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
network
low complexity
apache
5.0
2002-12-31 CVE-2002-2103 Unspecified vulnerability in Apache Http Server
Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
network
low complexity
apache
5.0
2002-12-31 CVE-2002-2012 Unspecified vulnerability in Apache Http Server 1.3.19
Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.
network
low complexity
apache
5.0
2002-12-31 CVE-2002-2007 Information Disclosure vulnerability in Apache Tomcat 3.2.3/3.2.4
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
network
low complexity
apache
5.0
2002-12-31 CVE-2002-1658 Buffer Overflow vulnerability in Multiple Apache HTDigest
Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument.
local
low complexity
apache
4.6
2002-05-29 CVE-2002-0249 Path Disclosure vulnerability in Apache Http Server 2.0.28
PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.
network
low complexity
apache
5.0
2002-05-29 CVE-2002-0240 Path Disclosure vulnerability in Apache Http Server 2.0.28
PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.
network
low complexity
apache
5.0
2002-03-22 CVE-2000-1210 Directory Traversal vulnerability in Apache Tomcat 1.1.3/3.0/3.1
Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a ..
network
low complexity
apache
5.0