First published: Wed Jan 01 1997(Updated: )
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP Server | ||
NCSA HTTPD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0236 is considered a critical severity vulnerability due to its potential for unauthorized access to sensitive CGI scripts.
To fix CVE-1999-0236, ensure that the ScriptAlias directives are properly configured to restrict access to CGI programs.
CVE-1999-0236 affects both the Apache HTTP Server and NCSA HTTPD software.
CVE-1999-0236 allows attackers to read sensitive CGI programs due to improper configuration.
A known workaround for CVE-1999-0236 is to review and secure your ScriptAlias settings in the server configuration.