Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http_server | Apache | 2.0.58 (including) | 2.0.58 (including) |
Http_server | Apache | 2.2.2 (including) | 2.2.2 (including) |
Http_server | Apache | 2.2.3 (including) | 2.2.3 (including) |