mod_auth_any: remote exploit
| Package(s): | mod_auth_any |
CVE #(s): | CAN-2003-0084
|
| Created: | May 2, 2003 |
Updated: | May 7, 2003 |
| Description: |
mod_auth_any is a web server module that allows the Apache httpd server to
call arbitrary external programs to verify user passwords.
Vulnerabilities have been found in the way mod_auth_any escapes shell
arguments when calling external programs. These vulnerabilities allow
remote attackers to run arbitrary commands as the user under which the Web
server is running. |
| Alerts: |
|