PoC Index

CVE-2006-3747

HIGH 7.6EPSS 96.6%

Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.

CVSS v2.0
7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
EPSS
96.58% chance of exploitation in the next 30 days, 100th percentile
Published
2006-07-28
Updated
2024-08-07

Proof-of-concept exploits (2)

Metasploit modules (1)

ExploitDB entries (4)

References

Related