Improper escaping of output in mod_rewrite in Apache HTTP Server two.four.59 and previously lets an attacker to map URLs to filesystem locations that are permitted to be served through the server but are not deliberately/straight reachable by any URL, causing code execution or source code disclosure. /var/log/apache2/obtain.log: By default, every https://emperorg310lxh2.wikievia.com/user