CVE-2004-0940

HIGH

HP-UX - Buffer Overflow in mod_include get_tag Function

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2004-0940. PoCs published by xCrZx.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the get_tag function of mod_include in Apache 1.3.x, allowing arbitrary code execution with the privileges of the httpd child process. The exploit generates a malicious HTML file that triggers the overflow when processed by the vulnerable Apache server.

Description

Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.

Exploits (2)

exploitdb WORKING POC VERIFIED
by xCrZx · clocallinux
https://www.exploit-db.com/exploits/587

This exploit targets a buffer overflow vulnerability in the get_tag function of mod_include in Apache 1.3.x, allowing arbitrary code execution with the privileges of the httpd child process. The exploit generates a malicious HTML file that triggers the overflow when processed by the vulnerable Apache server.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache 1.3.x (mod_include)
No auth needed
Prerequisites: Apache 1.3.x with mod_include enabled · XBitHack directive set to 'on' in httpd.conf · Ability to upload or serve malicious HTML file to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by xCrZx · clocallinux
https://www.exploit-db.com/exploits/24694

This exploit targets a buffer overflow in Apache 1.3.x's mod_include module via a maliciously crafted HTML file. It leverages improper length validation in the get_tag function to execute arbitrary code (bind shell) with httpd privileges.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache 1.3.x (mod_include)
No auth needed
Prerequisites: mod_include enabled (XBitHack on in httpd.conf) · ability to upload files to the server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (21)

Core 21
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_openpkg
http://marc.info/?l=bugtraq&m=109906660225051&w=2
Third Party Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm
Third Party Advisory vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2004:134
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17785
Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11471
Broken Link vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-816.html
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12898/
Mailing List, Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2004/dsa-594
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19073
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1011783
Broken Link vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2004-600.html
Broken Link vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102197-1
Broken Link vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0789

Scores

CVSS v3 7.8
EPSS 0.0483
EPSS Percentile 90.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-131
Status published
Products (21)
apache/http_server 1.3 - 1.3.32
hp/hp-ux 11.00
hp/hp-ux 11.11
hp/hp-ux 11.20
hp/hp-ux 11.22
openpkg/openpkg 2.0
openpkg/openpkg 2.1
openpkg/openpkg 2.2
slackware/slackware_linux 8.0
slackware/slackware_linux 8.1
... and 11 more
Published Feb 09, 2005
Tracked Since Feb 18, 2026