Vulnerability Database

290,206

Total vulnerabilities in the database

CVE-2004-0885

The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.

  • Published: Nov 3, 2004
  • Updated: Apr 13, 2023
  • CVE: CVE-2004-0885
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

No CWE or OWASP classifications available.

Software From Fixed in
apache / http_server 2.0.42 2.0.42.x
apache / http_server 2.0.47 2.0.47.x
apache / http_server 2.0.50 2.0.50.x
apache / http_server 2.0.35 2.0.35.x
apache / http_server 2.0.37 2.0.37.x
apache / http_server 2.0.44 2.0.44.x
apache / http_server 2.0.39 2.0.39.x
apache / http_server 2.0.52 2.0.52.x
apache / http_server 2.0.51 2.0.51.x
apache / http_server 2.0.41 2.0.41.x
apache / http_server 2.0.49 2.0.49.x
apache / http_server 2.0.38 2.0.38.x
apache / http_server 2.0.48 2.0.48.x
apache / http_server 2.0.45 2.0.45.x
apache / http_server 2.0.40 2.0.40.x
apache / http_server 2.0.36 2.0.36.x
apache / http_server 2.0.46 2.0.46.x
apache / http_server 2.0.43 2.0.43.x