Vulnerability Name:
CVE-2000-1206 (CCN-11139)
Assigned:
1999-08-20
Published:
1999-08-20
Updated:
2021-06-06
Summary:
Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
CVSS v3 Severity:
5.3 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
None
Availibility (A):
None
CVSS v2 Severity:
5.0 Medium
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
5.0 Medium
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Obtain Information
References:
Source: MITRE
Type: CNA
CVE-2000-1206
Source: CCN
Type: Apache HTTP Server Project Web site
Download - The Apache HTTP Server Project
Source: CCN
Type: ApacheWeek, Issue 181, 7th January 2000
Bugs in 1.3.9
Source: CONFIRM
Type: UNKNOWN
http://www.apacheweek.com/issues/00-01-07#status
Source: CCN
Type: OSVDB ID: 9691
Apache HTTP Server mod_rewrite Mass Virtual Hosting Arbitrary File Access
Source: CCN
Type: OSVDB ID: 9692
Apache HTTP Server mod_vhost_alias Mass Virtual Hosting Arbitrary File Access
Source: XF
Type: UNKNOWN
apache-virtualhosting-obtain-files(11139)
Source: MLIST
Type: UNKNOWN
[httpd-cvs] 20210330 svn commit: r1073140 [1/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
Source: MLIST
Type: UNKNOWN
[httpd-cvs] 20210603 svn commit: r1075360 [1/3] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2021-31618.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
Source: MLIST
Type: UNKNOWN
[httpd-cvs] 20210330 svn commit: r1073149 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/
Source: MLIST
Type: UNKNOWN
[httpd-cvs] 20210606 svn commit: r1075467 [1/2] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2021-31618.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
Source: MLIST
Type: UNKNOWN
[httpd-cvs] 20210606 svn commit: r1075470 [1/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
Source: MLIST
Type: UNKNOWN
[httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/
Vulnerable Configuration:
Configuration 1
:
cpe:/a:apache:http_server:1.3.10:*:*:*:*:*:*:*
OR
cpe:/a:apache:http_server:1.3.9:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:apache:http_server:1.3.9:*:*:*:*:*:*:*
OR
cpe:/a:apache:http_server:1.3.10:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
apache
http server 1.3.10
apache
http server 1.3.9
apache
http server 1.3.9
apache
http server 1.3.10