Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-7098

The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.0%
CVSS Severity
CVSS v2 Score 6.6
Products affected by CVE-2006-7098
  • Debian » Apache » Version: 1.3.34.4
    cpe:2.3:a:debian:apache:1.3.34.4


Contact Us

Shodan ® - All rights reserved