Sploitus

CVE-2006-3747

22 known exploits for CVE-2006-3747

Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.

Affected products
Apache, Apache Http Server, Hp-Ux
Apache Http Server
< 1.3.37, 2.0.59, 2.2.3
Fix
Available
CVSS 2.0
7.6 HIGH
EPSS
96.6% (100th percentile)
Weakness
CWE-189
NVD status
Modified
Published
2006-07-28
CVE-2006-3747 at NVD
Authoritative description, scoring and affected products

22 known exploits for CVE-2006-3747

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2006-3747
2026-08-29 KitPloitKITPLOIT
Apache < 1.3.37, 2.0.59, 2.2.3 (mod_rewrite) Remote Overflow PoC
2014-07-01 RootSEEBUG
Apache mod_rewrite - LDAP protocol Buffer Overflow (Metasploit)
2010-02-15 MetasploitEXPLOITDBRuby
Apache module mod_rewrite LDAP protocol Buffer Overflow
2009-11-26 patrickPACKETSTORMRuby
Apache Module mod_rewrite LDAP Protocol Buffer Overflow
2009-03-10 aushack <patrick@osisecurity.com.au>METASPLOITRuby
apache-mod-rewrite.rb.txt
2008-01-07 Marcin KozlowskiPACKETSTORMRuby
Apache mod_rewrite LDAP URL buffer overflow
2007-06-22 SAINT CorporationSAINT
Apache mod_rewrite LDAP URL buffer overflow
2007-06-22 SAINT CorporationSAINT
Apache mod_rewrite LDAP URL buffer overflow
2007-06-22 SAINT CorporationSAINT
Apache mod_rewrite LDAP URL buffer overflow
2007-06-22 SAINT CorporationSAINT
apache2058-rewrite.txt
2007-05-31 fabio/b0xPACKETSTORMC
Apache 2.0.58 mod_rewrite (Windows 2003) - Remote Overflow
2007-05-26 fabio/b0xEXPLOITDBC
Apache Mod_Rewrite Off-by-one Remote Overflow Exploit (win32)
2007-04-10 RootSEEBUG
Apache mod_rewrite (Windows x86) - Off-by-One Remote Overflow
2007-04-07 axisEXPLOITPACKBash
Apache mod_rewrite (Windows x86) - Off-by-One Remote Overflow
2007-04-07 axisEXPLOITDBBash
modrewrite-offbyone.txt
2007-04-07 axisPACKETSTORM
Apache mod_rewrite模块单字节缓冲区溢出漏洞
2006-11-05 RootSEEBUG
modrewritepoc.txt
2006-08-27 Jacobo Avariento GimenoPACKETSTORM
Apache < 1.3.37, 2.0.59, 2.2.3 (mod_rewrite) Remote Overflow PoC
2006-08-21 Jacobo AvarientoZDT
Apache 1.3.372.0.592.2.3 mod_rewrite - Remote Overflow
2006-08-21 Jacobo AvarientoEXPLOITPACKBash
Apache < 1.3.37/2.0.59/2.2.3 mod_rewrite - Remote Overflow
2006-08-21 Jacobo AvarientoEXPLOITDBBash
Apache < 1.3.37 2.0.59 2.2.3 (mod_rewrite) Remote Overflow PoC
2006-08-21 RootSEEBUG