CVE-2001-1556
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX…
Does this matter?
Lower severity and a low EPSS score (3.56%). Track it; it rarely justifies an emergency change on its own.
Description
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 3.56% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- apache/http server
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-10/0231.htmlBroken Link
- http://httpd.apache.org/docs/logs.htmlVendor Advisory
- http://www.iss.net/security_center/static/7363.phpBroken Link
- http://archives.neohapsis.com/archives/bugtraq/2001-10/0231.htmlBroken Link
- http://httpd.apache.org/docs/logs.htmlVendor Advisory
- http://www.iss.net/security_center/static/7363.phpBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.