CVE-2001-1556
Last modified
CVE-2001-1556 is a vulnerability of currently unknown severity. The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.. EPSS estimates a 3.56% chance of exploitation in the next 30 days.
Description
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | >= 1.3.0, < 1.3.31 |
| Apache | Http Server | >= 2.0.0, < 2.0.49 |
References
- http://httpd.apache.org/docs/logs.htmlVendor Advisory
- http://httpd.apache.org/docs/logs.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-1556?
How severe is CVE-2001-1556?
How do I fix CVE-2001-1556?
Are you affected by CVE-2001-1556?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
