Lucene search

K
cveMitreCVE-2009-3095
HistorySep 08, 2009 - 6:30 p.m.

CVE-2009-3095

2009-09-0818:30:00
mitre
web.nvd.nist.gov
486
2
apache
http server
mod_proxy_ftp
access restrictions
authorization header
ftp
security vulnerability
nvd
cve-2009-3095

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

9.4

Confidence

High

EPSS

0.008

Percentile

82.3%

The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.

Affected configurations

Nvd
Node
apachehttp_serverRange2.0.35–2.0.64
OR
apachehttp_serverRange2.2.0–2.2.14
Node
fedoraprojectfedoraMatch10
OR
fedoraprojectfedoraMatch12
Node
debiandebian_linuxMatch4.0
Node
opensuseopensuseMatch10.3
OR
opensuseopensuseMatch11.0
OR
opensuseopensuseMatch11.1
OR
suselinux_enterprise_desktopMatch10sp2
OR
suselinux_enterprise_desktopMatch10sp3
OR
suselinux_enterprise_serverMatch9
OR
suselinux_enterprise_serverMatch10sp2
OR
suselinux_enterprise_serverMatch10sp3-
OR
suselinux_enterprise_serverMatch11-
Node
applemac_os_xRange<10.6.3
VendorProductVersionCPE
apachehttp_server*cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
fedoraprojectfedora10cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:*
fedoraprojectfedora12cpe:2.3:o:fedoraproject:fedora:12:*:*:*:*:*:*:*
debiandebian_linux4.0cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
opensuseopensuse10.3cpe:2.3:o:opensuse:opensuse:10.3:*:*:*:*:*:*:*
opensuseopensuse11.0cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:*
opensuseopensuse11.1cpe:2.3:o:opensuse:opensuse:11.1:*:*:*:*:*:*:*
suselinux_enterprise_desktop10cpe:2.3:o:suse:linux_enterprise_desktop:10:sp2:*:*:*:*:*:*
suselinux_enterprise_desktop10cpe:2.3:o:suse:linux_enterprise_desktop:10:sp3:*:*:*:*:*:*
suselinux_enterprise_server9cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
Rows per page:
1-10 of 141

References

Social References

More

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

9.4

Confidence

High

EPSS

0.008

Percentile

82.3%