Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Apache Web Server MS-DOS Device Name Arbitrary Code Execution Vulnerability

A vulnerability has been reported in Apache Web server for Microsoft Windows. The vulnerability exists in the way some HTTP requests are handled by the Apache Web server. Specifically, HTTP requests that involve MS-DOS device names may cause the Apache Web server to execute malicious attacker-supplied code.

This exists if a malicious POST request is made to a CGI residing in a directory enabled with ScriptAlias.







 

Privacy Statement
Copyright 2008, SecurityFocus