ID:10986 - Exploit for Input validation error in Apache HTTP Server - CVE-2024-38475

 
Main Vulnerability Database Exploits ID:10986 - Exploit for Input validation error in Apache HTTP Server - CVE-2024-38475

ID:10986 - Exploit for Input validation error in Apache HTTP Server - CVE-2024-38475

Published: December 13, 2024


Vulnerability identifier: #VU93542
Vulnerability risk: Critical
CVE-ID: CVE-2024-38475
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
Apache HTTP Server

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input in mod_rewrite when first segment of substitution matches filesystem path. A remote attacker can map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL and view contents of files or execute arbitrary code.


Remediation

Install updates from vendor's website.