Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess mechanism is only intended to restrict external web access, and a local user already has the privileges to perform the same operations without using ErrorDocument
CVSS v2.0 Score
7.2
/ 10.0
HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
Information
- Published
- 31 déc. 2004
- Updated
- 16 avr. 2026
- Status
- Modified
- Source
- cve@mitre.org
Affected products
apache http serverAll Apache HTTP Server CVEs →
Versions : 2.0.47
Weaknesses (CWE)
NVD-CWE-Other
References (8)
Monitor your products
Get automatic alerts for every new CVE affecting your equipment.