Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-3095

Опубликовано: 08 сент. 2009
Источник: debian
EPSS Низкий

Описание

The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.2.13-2package
apache2no-dsaetchpackage
apache2fixed2.2.9-10+lenny5lennypackage

Примечания

  • The attacker needs to have valid credentials for the FTP server, which

  • makes this irrelevant in most cases. Based on a VulnDisco commercial 0day.

EPSS

Процентиль: 88%
0.03989
Низкий

Связанные уязвимости

ubuntu
почти 16 лет назад

The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.

redhat
почти 16 лет назад

The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.

nvd
почти 16 лет назад

The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.

github
около 3 лет назад

The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.

oracle-oval
больше 15 лет назад

ELSA-2009-1579: httpd security update (MODERATE)

EPSS

Процентиль: 88%
0.03989
Низкий