CVE-2006-2769
Snort 2.4.0-2.4.4 - HTTP Inspect Preprocessor Rule Bypass via Carriage Return
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2769. PoCs published by Blake Hartstein.
AI-analyzed exploit summary The exploit demonstrates a bypass vulnerability in Snort 2.4.4 by sending malformed HTTP requests with embedded null bytes or pipe characters. These requests may evade detection by Snort's intrusion detection system, allowing attackers to bypass security measures.
Description
The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriage return (\r) after the URL and before the HTTP declaration.
Exploits (1)
The exploit demonstrates a bypass vulnerability in Snort 2.4.4 by sending malformed HTTP requests with embedded null bytes or pipe characters. These requests may evade detection by Snort's intrusion detection system, allowing attackers to bypass security measures.