|
8.3
|
CVE-2025-58098: Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd= |
software
apache-test 2.4.37
|
cpe / high |
new |
2026-09-26T00:07:16Z |
|
8.3
|
CVE-2025-58098: Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd= |
software
apache-test2 2.4.37
|
cpe / high |
new |
2026-09-26T00:07:16Z |
|
7.5
|
CVE-2025-59775: Server-Side Request Forgery (SSRF) vulnerability
in Apache HTTP Server on Windows
with AllowEncodedSlashes On and MergeSlashes Off allows to potentially l |
software
apache-test 2.4.37
|
cpe / high |
new |
2026-09-26T00:07:16Z |
|
7.5
|
CVE-2025-59775: Server-Side Request Forgery (SSRF) vulnerability
in Apache HTTP Server on Windows
with AllowEncodedSlashes On and MergeSlashes Off allows to potentially l |
software
apache-test2 2.4.37
|
cpe / high |
new |
2026-09-26T00:07:16Z |
|
6.5
|
CVE-2025-65082: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration |
software
apache-test 2.4.37
|
cpe / high |
new |
2026-09-26T00:07:16Z |
|
6.5
|
CVE-2025-65082: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration |
software
apache-test2 2.4.37
|
cpe / high |
new |
2026-09-26T00:07:16Z |