|
|
Apache "mod_alias" Alias Directive Arguments and URL Handling Vulnerability
|
A vulnerability has been identified in Apache, which could be exploited by attackers to bypass security restrictions or disclose senstivie information. This flaw is due to an error in the "mod_alias" module when processing URLs containing directory names in capital letters on case-insensitive systems (i.e. Windows) configured with certain ScriptAlias directives, which could be exploited by attackers to disclose the source code of arbitrary files.
Apache version 2.0.59 and prior
Apache version 2.2.3 and prior
VUPEN Security is not aware of any vendor-supplied patch.
http://www.vupen.com/english/advisories/2006/3265 http://www.vupen.com/english/reference/18123
Vulnerability reported by Susam Pal
2006-08-11 : Initial release
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|