漏洞信息详情
Apache漏洞
漏洞简介
带mod_rewrite的Apache能够用在大多数UNIX系统上。远程攻击者通过插入额外的/(斜线)字符到请求的路径绕过RewriteRules,该漏洞导致RewriteRule的正规表达式失败。
漏洞公告
参考网址
来源: BID 名称: 3176 链接:http://www.securityfocus.com/bid/3176 来源: BUGTRAQ 名称: 20010812 Are your mod_rewrite rules doing what you expect? 链接:http://www.securityfocus.com/archive/1/203955 来源: XF 名称: apache-rewrite-bypass-directives(8633) 链接:http://xforce.iss.net/xforce/xfdb/8633 来源: www.apacheweek.com 链接:http://www.apacheweek.com/issues/02-02-01#security
受影响实体
- Apache Http_server:1.3.14<!--2000-1-1-->
- Apache Http_server:1.3.19<!--2000-1-1-->
- Apache Http_server:1.3.17<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...