First published: Fri Oct 11 2002(Updated: )
Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Http Server | =2.0.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1156 is considered a moderate severity vulnerability due to its potential for information disclosure.
To mitigate CVE-2002-1156, disable WebDAV support or upgrade to a version of Apache HTTP Server newer than 2.0.42.
CVE-2002-1156 affects Apache HTTP Server version 2.0.42 specifically.
Yes, CVE-2002-1156 can be exploited remotely by attackers to view the source code of CGI scripts.
Check your server configuration to ensure that CGI and WebDAV are not enabled simultaneously, as this can lead to vulnerabilities like CVE-2002-1156.