CVE-2013-1862

Description

mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
40.359

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.2.24Windows
Update Apache to version 2.0.65Windows
Multiple vulnerabilities are fixed in Apache 2.2.2Windows
Multiple vulnerabilities are fixed in Apache 2.0.65Windows
Vulnerabilities CVE-2013-1862 are affected in Oracle HTTP Server 5.1Windows
Update Apache to version 2.2.24 (For Linux)Linux
Update Apache to version 2.0.65 (For Linux)Linux
Apache HTTP Server mod_rewrite Log File Manipulation Vulnerability For Cisco Unified Computing SystemNCM
CVE-2013-1862NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706036Security Update for Cisco Unified Computing System 3.2(1d)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234