Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4m29-g52g-c6qc

Опубликовано: 05 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.3

Описание

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.

This issue affects Apache HTTP Server before 2.4.66.

Users are recommended to upgrade to version 2.4.66, which fixes the issue.

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.

This issue affects Apache HTTP Server before 2.4.66.

Users are recommended to upgrade to version 2.4.66, which fixes the issue.

EPSS

Процентиль: 5%
0.00023
Низкий

8.3 High

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 8.3
ubuntu
2 месяца назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
nvd
2 месяца назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
msrc
около 2 месяцев назад

Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

CVSS3: 8.3
debian
2 месяца назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) ...

oracle-oval
28 дней назад

ELSA-2026-0075: httpd security update (IMPORTANT)

EPSS

Процентиль: 5%
0.00023
Низкий

8.3 High

CVSS3

Дефекты

CWE-201