Vulnerability Name: | CCN-10415 | ||||||
Published: | 2002-10-16 | ||||||
Updated: | 2002-10-16 | ||||||
Summary: | Apache HTTP Server could allow a remote attacker to execute commands on the system, caused by an insecure system() call in support/htdigest.c:main(). A remote attacker could pass arbitrary commands to htdigest using one of the Apache CGI scripts, which could allow the attacker to execute commands on the Web server. | ||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Oct 16 2002 - 17:32:26 CDT Apache 1.3.26 Source: CCN Type: Apache Web site Welcome! - The Apache HTTP Server Project Source: CCN Type: BID-5981 Multiple Apache HTDigest and HTPassWD Component Vulnerabilites Source: CCN Type: BID-5991 Apache HTDigest Arbitrary Command Execution Vulnerability Source: XF Type: UNKNOWN apache-htdigest-command-execution(10415) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |