Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache HTTP服务器mod_auth_shadow模块竞争条件漏洞
Vulnerability Description
Apache HTTP Server(简称Apache)是Apache软件基金会的一个开放源码的网页服务器,可以在大多数计算机操作系统中运行,由于其多平台和安全性被广泛使用,是最流行的Web服务器端软件之一。它快速、可靠并且可通过简单的API扩展,将Perl/Python等解释器编译到服务器中。 Apache HTTP服务器的mod_auth_shadow模块存在竞争条件漏洞,远程攻击者可通过和外部帮助应用不正当交互的向量,获得凭证验证,从而躲避认证,读取甚至可能修改数据。
CVSS Information
N/A
Vulnerability Type
N/A