Total vulnerabilities in the database
Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
Software | From | Fixed in |
---|---|---|
apache / http_server | 1.3.23 | 1.3.23.x |
apache / http_server | 1.3.16 | 1.3.16.x |
apache / http_server | 1.3.19 | 1.3.19.x |
apache / http_server | 1.3.20 | 1.3.20.x |
apache / http_server | 1.3.13 | 1.3.13.x |
apache / http_server | 1.3.18 | 1.3.18.x |
apache / http_server | 1.3.12 | 1.3.12.x |
apache / http_server | 1.3.17 | 1.3.17.x |
apache / http_server | 1.3.9 | 1.3.9.x |
apache / http_server | 1.3.15 | 1.3.15.x |
apache / http_server | 1.3.14 | 1.3.14.x |
apache / http_server | 1.3.22 | 1.3.22.x |
apache / http_server | 1.3.11 | 1.3.11.x |