The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbit…
Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows r…
Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attac…
A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a fl…
A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the …
Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers wit…
Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a la…
Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
List of arbitrary files on Web host via nph-test-cgi script.
test-cgi program allows an attacker to list files on the server.
phf CGI program allows remote command execution through shell metacharacters.