CVE-2006-3918 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 95.1% (pctl 100)
Patch early
A public exploit exists.
Description
http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 95.1% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-07-28 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| apache | http server |
| canonical | ubuntu linux |
| debian | debian linux |
| redhat | enterprise linux server |
| redhat | enterprise linux workstation |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apache 1.3.35/2.0.58/2.2.2 - Arbitrary HTTP Request Headers Security | 2006-08-24 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P
- http://archives.neohapsis.com/archives/bugtraq/2006-05/0151.html
- http://archives.neohapsis.com/archives/bugtraq/2006-07/0425.html
- http://kb.vmware.com/KanisaPlatform/Publishing/466/5915871_f.SAL_Public.html
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html
- http://marc.info/?l=bugtraq&m=125631037611762&w=2
- http://marc.info/?l=bugtraq&m=129190899612998&w=2
- http://marc.info/?l=bugtraq&m=130497311408250&w=2
- http://openbsd.org/errata.html#httpd2
- http://rhn.redhat.com/errata/RHSA-2006-0618.html
- http://rhn.redhat.com/errata/RHSA-2006-0692.html
- http://secunia.com/advisories/21172
- http://secunia.com/advisories/21174
- http://secunia.com/advisories/21399
- http://secunia.com/advisories/21478
- http://secunia.com/advisories/21598
- http://secunia.com/advisories/21744
- http://secunia.com/advisories/21848
- http://secunia.com/advisories/21986
- http://secunia.com/advisories/22140
→ the Explorer · watch your stack · NVD