CVE Vulnerabilities

CVE-2009-3095

Published: Sep 08, 2009 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.

Affected Software

Name Vendor Start Version End Version
Http_server Apache 2.0.35 (including) 2.0.64 (excluding)
Http_server Apache 2.2.0 (including) 2.2.14 (excluding)

References