CVE-2003-1418

Description

Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.303

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are affected in Oracle HTTP Server 11.1.1.9.0Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 12.1.3.0.0Windows
Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2003-1418)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234