Vulnerabilidad en mod_rewrite en Apache (CVE-2000-0913)
Gravedad CVSS v2.0:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/12/2000
Última modificación:
23/09/2026
Descripción
mod_rewrite en Apache 1.3.12 y versiones anteriores permite a atacantes remotos leer archivos arbitrarios si una directiva RewriteRule se expande para incluir un nombre de archivo cuyo nombre contiene una expresión regular.
Impacto
Puntuación base 2.0
5.00
Gravedad 2.0
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:apache:http_server:0.8.11:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:http_server:0.8.14:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:http_server:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:http_server:1.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:http_server:1.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:http_server:1.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:http_server:1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:http_server:1.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:http_server:1.3.11:*:win32:*:*:*:*:* | ||
| cpe:2.3:a:apache:http_server:1.3.12:*:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- http://archives.neohapsis.com/archives/bugtraq/2000-09/0352.html
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0174.html
- http://archives.neohapsis.com/archives/hp/2000-q4/0021.html
- http://www.calderasystems.com/support/security/advisories/CSSA-2000-035.0.txt
- http://www.linux-mandrake.com/en/security/MDKSA-2000-060-2.php3?dis=7.1
- http://www.redhat.com/support/errata/RHSA-2000-088.html
- http://www.redhat.com/support/errata/RHSA-2000-095.html
- http://www.securityfocus.com/bid/1728
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5310
- https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
- http://archives.neohapsis.com/archives/bugtraq/2000-09/0352.html
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0174.html
- http://archives.neohapsis.com/archives/hp/2000-q4/0021.html
- http://www.calderasystems.com/support/security/advisories/CSSA-2000-035.0.txt
- http://www.linux-mandrake.com/en/security/MDKSA-2000-060-2.php3?dis=7.1
- http://www.redhat.com/support/errata/RHSA-2000-088.html
- http://www.redhat.com/support/errata/RHSA-2000-095.html
- http://www.securityfocus.com/bid/1728
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5310
- https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E


