This application requires Javascript for optimal performance.

Apache.BAT.Command.Execution

Alias(es)

Apache.CMD.Command.Execution.A

Release Date

Sep 11, 2006

Severity

high

Impact

Attackers can execute arbitrary commands on the victim system.

Description

This indicates a potentially malicious attempt to execute commands on an Apache Web Server.

Apache Web Server is an open source solution to building a secure modern web server that is compatible with both UNIX and Windows operating systems. Due to inadequate user input checking, a remote attacker can execute arbitrary commands on a target system by sending it a specially crafted message.

Affected Products

Any unprotected Apache HTTP Server versions 1.3.23 and earlier or versions 2.0.28 Beta is vulnerable to the attack.

Recommended Actions

Update to Apache Group Apache 1.3.24 or newer.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2002-0061
CVE-1999-0947

Reference/s

http://www.ciac.org/ciac/bulletins/m-070.shtml
http://www.securityfocus.com/bid/4335 (BugTraq)
http://www.kb.cert.org/vuls/id/124003

Reference: VID-13011