Apache HTTP Server
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*
- >= 2.4.7, <= 2.4.65
A vulnerability has been identified in Apache HTTP Server versions 2.4.7 prior to 2.4.65, allowing for a mod_userdir and suexec bypass. This issue arises from the AllowOverride FileInfo directive, which enables users to manipulate the RequestHeader directive in .htaccess files. By doing so, they can cause certain CGI scripts to execute under an unexpected user ID, potentially leading to unauthorized actions or access.
Exploitation of this vulnerability can cause some CGI scripts to run under an unexpected user ID, which could lead to unauthorized access or actions on behalf of that user.
Users are advised to upgrade to Apache HTTP Server version 2.4.66, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.