Apache HTTPd 漏洞列表
共找到 2 个与 Apache HTTPd 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2017-15715: Apache httpd <=2.4.29 - Arbitrary File Upload POC
Apache httpd 2.4.0 to 2.4.29 is susceptible to arbitrary file upload vulnerabilities via the expression specified in <FilesMatch>, which could match '$' to a newline character in a malicious filename rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are externally blocked, but only by matching the trailing portion of the filename. -
CVE-2024-38472: Apache HTTPd Windows UNC - Server-Side Request Forgery POC
SSRF in Apache HTTP Server on Windows allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note- Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.