CVE-2006-3747
HIGH 7.6EPSS 96.6%
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
- CVSS v2.0
- 7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C - EPSS
- 96.58% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2006-07-28
- Updated
- 2024-08-07
Proof-of-concept exploits (2)
- http://www.securityfocus.com/archive/1/443870/100/0/threaded
- defensahacker/CVE-2006-37472★ · 2021-03-14
Metasploit modules (1)
ExploitDB entries (4)
- https://www.exploit-db.com/exploits/16752
- https://www.exploit-db.com/exploits/3996
- https://www.exploit-db.com/exploits/3680
- https://www.exploit-db.com/exploits/2237