Arbitrary Code Execution The advisory has been revoked - it doesn't affect any version of package apache/httpd  (opens in a new tab)


Threat Intelligence

EPSS
9.57% (95th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-APACHEHTTPD-3007230
  • published12 Jan 2022
  • disclosed16 Feb 2001
  • creditUnknown

Introduced: 16 Feb 2001

CVE-2001-0042  (opens in a new tab)
CWE-94  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Arbitrary Code Execution. PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.

References