5
CVSSv2

CVE-1999-0236

Published: 01/01/1997 Updated: 17/08/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

ScriptAlias directory in NCSA and Apache httpd allowed malicious users to read CGI programs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache http server -

illinois ncsa httpd -

Exploits

source: wwwsecurityfocuscom/bid/2300/info NSCA httpd prior to and including 15 and Apache Web Server prior to 10 contain a bug in the ScriptAlias function that allows remote users to view the source of CGI programs on the web server, if a ScriptAlias directory is defined under DocumentRoot A full listing of the CGI-BIN directory can be ...