DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG 
RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT
<http://nagoya.apache.org/bugzilla/show_bug.cgi?id=19531>.
ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND 
INSERTED IN THE BUG DATABASE.

http://nagoya.apache.org/bugzilla/show_bug.cgi?id=19531

apache accetps  everything as HTTP Version





------- Additional Comments From [EMAIL PROTECTED]  2003-05-02 14:17 -------
Ok, one other point:

as long as one can write %s %d ... to logfiles p.ex.
"GET / HTTP/%s%s.%d"

it is also possible to "confuse" log analizers programs.

As Steve Grubb had pointed out p.ex. on bugtraq.vuln-dev along with the
"Apache 2.x leaked descriptors" problem:
"In the past, there have been vulnerable versions of these programs."

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to