Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-58098

Опубликовано: 05 дек. 2025
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

A server side include handling flaw has been discovered in the Apache HTTP server. When Server Side Includes (SSI) areenabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives an attacker may be able to inject commands executed by the server.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2419365httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

EPSS

Процентиль: 7%
0.00027
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
4 месяца назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
nvd
4 месяца назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
msrc
4 месяца назад

Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

CVSS3: 8.3
debian
4 месяца назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) ...

CVSS3: 8.3
github
4 месяца назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

EPSS

Процентиль: 7%
0.00027
Низкий

7.1 High

CVSS3