7.5
CVSSv2

CVE-2001-0766

Published: 18/10/2001 Updated: 02/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote malicious users to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.

Vulnerable Product Search on Vulmon Subscribe to Product

apache http_server 1.3.14

Exploits

source: wwwsecurityfocuscom/bid/2852/info A vulnerability exists when Apache webserver is used with Mac OS X Client The standard filesystem for Mac OS X is HFS+ HFS+ is case insensitive while Apache's filtering is case sensitive The result is that Apache will filter all file requests that match filters exactly (including case), but it ...