New Search

Apache Error Log Escape Sequence Injection Vulnerability

oval:org.mitre.oval:def:4114

Apache does not filter terminal escape sequences from its error logs which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.

Family:
unix
Status:
ACCEPTED
Platform(s):
  • Sun Solaris 8
  • Sun Solaris 9
Class:
vulnerability
Reference(s):
  • CVE-2003-0020
Product(s):
  • Apache