CVE-2003-0083
Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.
- Affected products
- Apache, Apache Http Server
- Apache Http Server
- < 1.3.26, 2.0.46
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 17.4% (97th percentile)
- NVD status
- Modified
- Published
- 2003-03-28
CVE-2003-0083 at NVD
8 known exploits for CVE-2003-0083
Proof-of-concept code and exploit modules indexed by Sploitus
jetty 6.x - 7.x xss, information disclosure, injection
Nginx, Varnish, Cherokee, etc Log Injection
jetty 6.x 7.x - Cross-Site Scripting Information Disclosure Injection
Jetty 6.x / 7.x Information Disclosure / XSS
jetty 6.x - 7.x xss information disclosure injection
jetty 6.x - 7.x xss information disclosure injection
jetty 6.x - 7.x xss, information disclosure, injection
Apache终端转义序列过滤漏洞