CVE-2001-0766

CRITICAL

Apache on MacOS X Client 10.0.3 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0766. PoCs published by Stefan Arentz.

AI-analyzed exploit summary This writeup describes a case sensitivity vulnerability in Apache on Mac OS X (HFS+ filesystem) where case-insensitive paths bypass case-sensitive filters, leading to unauthorized file disclosure.

Description

Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Stefan Arentz · textremoteosx
https://www.exploit-db.com/exploits/20911

This writeup describes a case sensitivity vulnerability in Apache on Mac OS X (HFS+ filesystem) where case-insensitive paths bypass case-sensitive filters, leading to unauthorized file disclosure.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Apache on Mac OS X (HFS+ filesystem)
No auth needed
Prerequisites: Apache running on Mac OS X with HFS+ filesystem
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Broken Link, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2001-06/0090.html
Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2852

Scores

CVSS v3 9.8
EPSS 0.1113
EPSS Percentile 93.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-178
Status published
Products (1)
apache/http_server 1.3.14
Published Oct 18, 2001
Tracked Since Feb 18, 2026