CVE-2004-0940
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
- Affected products
- Apache, Apache Http Server
- Apache Http Server
- ≤ 1.3.32
- Openpkg
- = 2.0, 2.1, 2.2
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 4.8% (91th percentile)
- Weakness
- CWE-131
- NVD status
- Modified
- Published
- 2004-10-26
CVE-2004-0940 at NVD
2 known exploits for CVE-2004-0940
Proof-of-concept code and exploit modules indexed by Sploitus