Vulnerability Details CVE-2002-1233
A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.1%
CVSS Severity
CVSS v2 Score 2.6
Products affected by CVE-2002-1233
-
cpe:2.3:a:apache:http_server:1.3.17
-
cpe:2.3:a:apache:http_server:1.3.18
-
cpe:2.3:a:apache:http_server:1.3.19
-
cpe:2.3:a:apache:http_server:1.3.20
-
cpe:2.3:a:apache:http_server:1.3.22
-
cpe:2.3:a:apache:http_server:1.3.23
-
cpe:2.3:a:apache:http_server:1.3.24
-
cpe:2.3:a:apache:http_server:1.3.25
-
cpe:2.3:a:apache:http_server:1.3.26
-
cpe:2.3:a:apache:http_server:1.3.27