Description
Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.
Remediation
References
Related Vulnerabilities
WordPress Incorrect Authorization Vulnerability (CVE-2018-20147)
MediaWiki Insecure Storage of Sensitive Information Vulnerability (CVE-2021-36127)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-5900)
WordPress Plugin ProPlayer 'pp_playlist_id' Parameter SQL Injection (4.7.7)
XWikiplatform Improper Encoding or Escaping of Output Vulnerability (CVE-2024-55663)