Vulnerability Name:
CVE-2000-1204 (CCN-11088)
Assigned:
2000-10-13
Published:
2000-10-13
Updated:
2021-06-06
Summary:
Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.
CVSS v3 Severity:
5.3 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
None
Availibility (A):
None
CVSS v2 Severity:
5.0 Medium
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
5.0 Medium
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Obtain Information
References:
Source: MITRE
Type: CNA
CVE-2000-1204
Source: CCN
Type: Apache HTTP Server Project Web site
Download - The Apache HTTP Server Project
Source: CCN
Type: ApacheWeek, Issue 218, 13th October 2000
Apache 1.3.14 Released
Source: CONFIRM
Type: Exploit, Vendor Advisory
http://www.apacheweek.com/issues/00-10-13
Source: CCN
Type: OSVDB ID: 9690
Apache HTTP Server mod_vhost_alias CGI Program Source Disclosure
Source: XF
Type: UNKNOWN
apache-modvhostalias-source-disclosure(11088)
Source: MLIST
Type: UNKNOWN
[httpd-cvs] 20210330 svn commit: r1073140 [1/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
Source: MLIST
Type: UNKNOWN
[httpd-cvs] 20210603 svn commit: r1075360 [1/3] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2021-31618.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
Source: MLIST
Type: UNKNOWN
[httpd-cvs] 20210330 svn commit: r1073149 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/
Source: MLIST
Type: UNKNOWN
[httpd-cvs] 20210606 svn commit: r1075467 [1/2] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2021-31618.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
Source: MLIST
Type: UNKNOWN
[httpd-cvs] 20210606 svn commit: r1075470 [1/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
Source: MLIST
Type: UNKNOWN
[httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/
Vulnerable Configuration:
Configuration 1
:
cpe:/a:apache:http_server:1.3.12:*:*:*:*:*:*:*
OR
cpe:/a:apache:http_server:1.3.11:*:*:*:*:*:*:*
OR
cpe:/a:apache:http_server:1.3.9:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:apache:http_server:1.3.9:*:*:*:*:*:*:*
OR
cpe:/a:apache:http_server:1.3.12:*:*:*:*:*:*:*
OR
cpe:/a:apache:http_server:1.3.11:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
apache
http server 1.3.12
apache
http server 1.3.11
apache
http server 1.3.9
apache
http server 1.3.9
apache
http server 1.3.12
apache
http server 1.3.11