CVE-2001-1556
Last modified
CVE-2001-1556 is a vulnerability of currently unknown severity. The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.. EPSS estimates a 3.56% chance of exploitation in the next 30 days.
Description
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | >= 1.3.0, < 1.3.31 |
| Apache | Http Server | >= 2.0.0, < 2.0.49 |
References
- http://httpd.apache.org/docs/logs.htmlVendor Advisory
- http://httpd.apache.org/docs/logs.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-1556?
How severe is CVE-2001-1556?
How do I fix CVE-2001-1556?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2001
- CVE-2001-1550CentraOne 5.2 and Centra ASP with basic authentication enabl…
- CVE-2001-1551Linux kernel 2.2.19 enables CAP_SYS_RESOURCE for setuid proc…
- CVE-2001-1552ssdpsrv.exe in Windows ME allows remote attackers to cause a…
- CVE-2001-1553Buffer overflow in setiathome for SETI@home 3.03, if install…
- CVE-2001-1554IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allo…
- CVE-2001-1555pt_chmod in Solaris 8 does not call fdetach to reset termina…
- CVE-2001-1557Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attack…
- CVE-2001-1558Unknown vulnerability in IP defragmenter (frag2) in Snort be…
- CVE-2001-1559The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3…5.5
- CVE-2001-1560Win32k.sys (aka Graphics Device Interface (GDI)) in Windows …
- CVE-2001-1561Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local …
- CVE-2001-1562Format string vulnerability in nvi before 1.79 allows local …
Are you affected by CVE-2001-1556?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
