Apache
Server Status
Apache server-status is an Apache monitoring instance Available by default at http://$target/server-status
In normal cases, the server-status instance is not accessible by non-local IPs. However, due to misconfiguration, it can be publicly accessible. This leads anyone to view the great amount of data by server-status.
Data exposed
All URL requested by all hosts/vhosts, including obscure files/directories and session tokens
All requested client's IPs
Exploiting it
CVE-2021-41773
Last updated
Was this helpful?