Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
Link | Tags |
---|---|
http://www.apacheweek.com/issues/02-02-01#security | |
http://www.securityfocus.com/bid/3176 | vdb entry patch vendor advisory |
http://www.securityfocus.com/archive/1/203955 | mailing list patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8633 | vdb entry |