Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11104
HistoryJan 15, 2019 - 8:57 a.m.

Remote Code Execution (RCE)

2019-01-1508:57:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.383 Low

EPSS

Percentile

97.2%

httpd is vulnerable to remote code execution (RCE). The mod_rewrite.c in the mod_rewrite module does not sanitize non-printable characters before writing to a log file, allowing a remote attacker to inject escape sequences for a terminal emulator into the log file via an HTTP request, resulting in execution of arbitrary commands.

References