Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
Software | From | Fixed in |
---|---|---|
apache / http_server | 1.3.14 | 1.3.14.x |
apache / http_server | 1.3.17 | 1.3.17.x |
apache / http_server | 1.3.19 | 1.3.19.x |