peter bassill · operator
$ cve CVE-2011-3368 JSON

CVE-2011-3368 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 90.7% (pctl 100)

Patch early

A public exploit exists.

Description

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS90.73% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2011-10-05
Last modified2026-06-16

Affected (1)

VendorProduct
apachehttp server

Public exploits

SourceTitleDate
exploit-dbApache mod_proxy - Reverse Proxy Exposure2011-10-11

References

→ the Explorer  ·  watch your stack  ·  NVD