mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 10:41:43 +00:00
32 lines
1.4 KiB
Markdown
32 lines
1.4 KiB
Markdown
![]() |
### [CVE-2009-1195](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1195)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
No PoCs from references.
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/ARPSyndicate/cvemon
|
||
|
- https://github.com/DButter/whitehat_public
|
||
|
- https://github.com/Dokukin1/Metasploitable
|
||
|
- https://github.com/GiJ03/ReconScan
|
||
|
- https://github.com/Iknowmyname/Nmap-Scans-M2
|
||
|
- https://github.com/NikulinMS/13-01-hw
|
||
|
- https://github.com/RoliSoft/ReconScan
|
||
|
- https://github.com/SecureAxom/strike
|
||
|
- https://github.com/Zhivarev/13-01-hw
|
||
|
- https://github.com/issdp/test
|
||
|
- https://github.com/kasem545/vulnsearch
|
||
|
- https://github.com/matoweb/Enumeration-Script
|
||
|
- https://github.com/smabramov/Vulnerabilities-and-attacks-on-information-systems
|
||
|
- https://github.com/xxehacker/strike
|
||
|
- https://github.com/zzzWTF/db-13-01
|
||
|
|