VYPR

mod_auth_shadow

by Apache

CVEs (2)

  • CVE-2010-1151Apr 20, 2010
    risk 0.00cvss epss 0.04

    Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.

  • CVE-2005-2963Oct 13, 2005
    risk 0.00cvss epss 0.02

    The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to…