CVE-2001-0730
published 2001-10-30CVE-2001-0730: split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the…
PriorityP427medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
11.92%
95.7th percentile
split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x7jp-wrv8-52h3: split-logfile in Apache 1
ghsa_unreviewed·2022-04-30
CVE-2001-0730 [MEDIUM] GHSA-x7jp-wrv8-52h3: split-logfile in Apache 1
split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.
Red Hat
security flaw
vendor_redhat·2001-09-28·CVSS 5.0
CVE-2001-0730 [MEDIUM] security flaw
security flaw
split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2001-0730 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2001-0730 [MEDIUM] CVE-2001-0730 security flaw
CVE-2001-0730 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.
arXiv
Encoding a Taxonomy of Web Attacks with Different-Length Vectors
arxiv_fulltext·2002-10-29
Encoding a Taxonomy of Web Attacks with Different-Length Vectors
## Abstract
Web attacks, i.e. attacks exclusively using the HTTP protocol, are
rapidly becoming one of the fundamental threats for information
systems connected to the Internet. When the attacks suffered by
web servers through the years are analyzed, it is observed that
most of them are very similar, using a reduced number of attacking
techniques. It is generally agreed that classification can help
designers and programmers to better understand attacks and build
more secure applications. As an effort in this direction, a new
taxonomy of web attacks is proposed in this paper, with the
objective of obtaining a practically useful reference framework
for security applications. The use of the taxonomy is illustrated
by means of multiplatform real world web attack examples. Along
with this taxo
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000430http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:077http://www.apacheweek.com/issues/01-09-28#securityhttp://www.linuxsecurity.com/advisories/other_advisory-1649.htmlhttp://www.redhat.com/support/errata/RHSA-2001-126.htmlhttp://www.redhat.com/support/errata/RHSA-2001-164.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/7419https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000430http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:077http://www.apacheweek.com/issues/01-09-28#securityhttp://www.linuxsecurity.com/advisories/other_advisory-1649.htmlhttp://www.redhat.com/support/errata/RHSA-2001-126.htmlhttp://www.redhat.com/support/errata/RHSA-2001-164.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/7419https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
2001-10-30
Published