Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-1195

Опубликовано: 28 мая 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.9

Описание

The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.

РелизСтатусПримечание
dapper

not-affected

2.0.55-4ubuntu2.4
devel

not-affected

2.2.11-6ubuntu1
hardy

released

2.2.8-1ubuntu0.8
intrepid

released

2.2.9-7ubuntu3.1
jaunty

released

2.2.11-2ubuntu2.1
upstream

released

2.2.11-6

Показывать по

EPSS

Процентиль: 44%
0.00216
Низкий

4.9 Medium

CVSS2

Связанные уязвимости

redhat
около 16 лет назад

The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.

nvd
около 16 лет назад

The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.

debian
около 16 лет назад

The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not proper ...

github
около 3 лет назад

The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.

oracle-oval
около 16 лет назад

ELSA-2009-1075: httpd security update (MODERATE)

EPSS

Процентиль: 44%
0.00216
Низкий

4.9 Medium

CVSS2