Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rxhx-8qf3-fc8h

Опубликовано: 01 окт. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.

This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.

This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

EPSS

Процентиль: 12%
0.00228
Низкий

3.7 Low

CVSS3

Дефекты

CWE-430

Связанные уязвимости

CVSS3: 3.7
redhat
2 дня назад

A flaw was found in Apache HTTP Server. An attacker could achieve unintended code execution when an internal redirect generated by a Common Gateway Interface (CGI) program points to a non-executable file. If the target file resides in a directory configured for CGI execution and lacks a file extension recognized by the MIME handler, the server incorrectly treats and executes the target file as a script. This issue could allow an attacker to run unauthorized commands or code within the server context.

CVSS3: 3.7
nvd
2 дня назад

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

CVSS3: 3.7
debian
2 дня назад

Deployment of wrong handler vulnerability in Apache HTTP Server allows ...

EPSS

Процентиль: 12%
0.00228
Низкий

3.7 Low

CVSS3

Дефекты

CWE-430