peter bassill · operator
$ cve CVE-2006-3747 JSON

CVE-2006-3747 EXPLOIT

7.6
HIGH · CVSS 2.0 · EPSS 96.6% (pctl 100)

Patch early

A public exploit exists.

Description

Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.

Scoring

CVSS7.6 (HIGH, v2.0)
VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
EPSS96.58% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-189
On CISA KEVno
Public exploityes
Published2006-07-28
Last modified2026-06-16

Affected (3)

VendorProduct
apachehttp server
canonicalubuntu linux
debiandebian linux

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD