Exploitation Summary
EIP tracks 1 public exploit for CVE-2001-0766. PoCs published by Stefan Arentz.
AI-analyzed exploit summary This writeup describes a case sensitivity vulnerability in Apache on Mac OS X (HFS+ filesystem) where case-insensitive paths bypass case-sensitive filters, leading to unauthorized file disclosure.
Description
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Stefan Arentz · textremoteosx
https://www.exploit-db.com/exploits/20911
This writeup describes a case sensitivity vulnerability in Apache on Mac OS X (HFS+ filesystem) where case-insensitive paths bypass case-sensitive filters, leading to unauthorized file disclosure.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
Apache on Mac OS X (HFS+ filesystem)
No auth needed
Prerequisites:
Apache running on Mac OS X with HFS+ filesystem
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (2)
Core 2
Core References
Broken Link, Patch, Vendor Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2001-06/0090.html
Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/2852
Scores
CVSS v3
9.8
EPSS
0.1113
EPSS Percentile
93.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-178
Status
published
Products (1)
apache/http_server
1.3.14
Published
Oct 18, 2001
Tracked Since
Feb 18, 2026