4.3
CVSSv2

CVE-2007-6514

Published: 21/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote malicious users to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.

Vulnerable Product Search on Vulmon Subscribe to Product

apache http_server 2.2.6

apache http server 2.2.6

Exploits

source: wwwsecurityfocuscom/bid/26939/info Apache is prone to an information-disclosure vulnerability This issue occurs because Apache fails to properly associate file extensions with the correct engines when handling specially crafted requests for files on Windows SMB shares Attackers can leverage this issue to view arbitrary script ...