CVE-2001-0042: Medium severity Apache HTTP Server vulnerability
Published Feb 16, 2001
·Updated
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.
Affected Software
1 affected component
Apache HTTP Server=1.3
Event History
Feb 16, 2001
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0042?
CVE-2001-0042 is considered to be of moderate severity due to its ability to allow unauthorized file access.
2
How do I fix CVE-2001-0042?
To fix CVE-2001-0042, update Apache HTTP Server to a version that is not vulnerable to this path traversal issue.
3
Which versions of Apache are affected by CVE-2001-0042?
CVE-2001-0042 affects Apache HTTP Server version 1.3.6 specifically.
4
What does CVE-2001-0042 exploit?
CVE-2001-0042 exploits a vulnerability in PHP 3.x on Apache 1.3.6 that allows attackers to read arbitrary files using a dot dot attack.
5
Who can be impacted by CVE-2001-0042?
Web servers running affected versions of Apache with PHP 3.x are at risk of exploitation due to CVE-2001-0042.