CVE-2006-2769

Snort 2.4.0-2.4.4 - HTTP Inspect Preprocessor Rule Bypass via Carriage Return

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-2769. PoCs published by Blake Hartstein.

AI-analyzed exploit summary The exploit demonstrates a bypass vulnerability in Snort 2.4.4 by sending malformed HTTP requests with embedded null bytes or pipe characters. These requests may evade detection by Snort's intrusion detection system, allowing attackers to bypass security measures.

Description

The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriage return (\r) after the URL and before the HTTP declaration.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Blake Hartstein · textremotemultiple
https://www.exploit-db.com/exploits/27931

The exploit demonstrates a bypass vulnerability in Snort 2.4.4 by sending malformed HTTP requests with embedded null bytes or pipe characters. These requests may evade detection by Snort's intrusion detection system, allowing attackers to bypass security measures.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Snort 2.4.4
No auth needed
Prerequisites: Network access to the target Snort instance · Ability to send crafted HTTP requests to the target
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (16)

Core 16
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/435872/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/435734/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20766
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18200
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20413
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/435600/100/0/threaded
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2119
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1018
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26855
Exploit, Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/25837
Various Sources vendor-advisory x_refsource_suse
http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.html
Exploit, Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016191
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=snort-devel&m=114909074311462&w=2
Various Sources x_refsource_confirm
http://www.snort.org/pub-bin/snortnews.cgi#431
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/435797/100/0/threaded

Scores

EPSS 0.1081
EPSS Percentile 95.4%

Details

CWE
CWE-264
Status published
Products (5)
sourcefire/snort 2.4
sourcefire/snort 2.4.1
sourcefire/snort 2.4.2
sourcefire/snort 2.4.3
sourcefire/snort 2.4.4
Published Jun 02, 2006
Tracked Since Feb 18, 2026