Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4m29-g52g-c6qc

Опубликовано: 05 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.3

Описание

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.

This issue affects Apache HTTP Server before 2.4.66.

Users are recommended to upgrade to version 2.4.66, which fixes the issue.

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.

This issue affects Apache HTTP Server before 2.4.66.

Users are recommended to upgrade to version 2.4.66, which fixes the issue.

EPSS

Процентиль: 21%
0.00069
Низкий

8.3 High

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 8.3
ubuntu
12 дней назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
nvd
12 дней назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

msrc
7 дней назад

Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

CVSS3: 8.3
debian
12 дней назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) ...

CVSS3: 8.3
fstec
4 месяца назад

Уязвимость модуля mod_cgid веб-сервера Apache HTTP Server, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 21%
0.00069
Низкий

8.3 High

CVSS3

Дефекты

CWE-201