CVE-2003-0020
Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
- Affected products
- Apache, Apache Http Server
- Apache Http Server
- < 1.3.31, 2.0.49
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 16.5% (97th percentile)
- NVD status
- Modified
- Published
- 2004-09-01
CVE-2003-0020 at NVD
7 known exploits for CVE-2003-0020
Proof-of-concept code and exploit modules indexed by Sploitus
jetty 6.x - 7.x xss, information disclosure, injection
Nginx, Varnish, Cherokee, etc Log Injection
jetty 6.x 7.x - Cross-Site Scripting Information Disclosure Injection
Jetty 6.x / 7.x Information Disclosure / XSS
jetty 6.x - 7.x xss information disclosure injection
jetty 6.x - 7.x xss information disclosure injection
jetty 6.x - 7.x xss, information disclosure, injection