Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: BUG IN APACHE HTTPD SERVER (current version 2.0.47)

Re: BUG IN APACHE HTTPD SERVER (current version 2.0.47)

From: André Malo <nd_at_perlig.de>
Date: Tue, 3 Feb 2004 06:39:33 +0100

* Vietnamese Security Group <security_at_security.com.vn> wrote:

[snakeoil]

> Event if the server does not allow any file parsed (Deny From All),
> the script file fetch.php will still be executed, and it includes
> again and parses any other files in a same directory, which
> indecated by the query variables, to the web client.

Deny from all (in conclusion with some other) denies HTTP access on some
criteria. It doesn't suppose to protect against access from inside the
server.

> I post this issue in the public mailing list, because I think this
> vuln is not exploitable by a remote attacker. If something were
> wrong, drop a line to me.

Next time, try a user support forum first. Thanks.

nd
Received on Feb 03 2004

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos