Описание
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.
This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.
EPSS
3.7 Low
CVSS3
Дефекты
Связанные уязвимости
A flaw was found in Apache HTTP Server. An attacker could achieve unintended code execution when an internal redirect generated by a Common Gateway Interface (CGI) program points to a non-executable file. If the target file resides in a directory configured for CGI execution and lacks a file extension recognized by the MIME handler, the server incorrectly treats and executes the target file as a script. This issue could allow an attacker to run unauthorized commands or code within the server context.
Deployment of wrong handler vulnerability in Apache HTTP Server allows ...
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.
EPSS
3.7 Low
CVSS3