CVE-2006-3747

Apache HTTP Server 1.3.28-1.3.36 & 2.0.46-2.0.58 - DoS & RCE via mod_rewrite LDAP Handling

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 6 public exploits for CVE-2006-3747. PoCs published by Metasploit, fabio/b0x, axis, including Metasploit module exploits/windows/http/apache_mod_rewrite_ldap.

AI-analyzed exploit summary This Metasploit module exploits an off-by-one buffer overflow in Apache's mod_rewrite LDAP protocol handling (CVE-2006-3747). It targets Windows systems by sending a maliciously crafted LDAP URI to trigger the vulnerability and execute arbitrary code.

Description

Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16752

This Metasploit module exploits an off-by-one buffer overflow in Apache's mod_rewrite LDAP protocol handling (CVE-2006-3747). It targets Windows systems by sending a maliciously crafted LDAP URI to trigger the vulnerability and execute arbitrary code.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache HTTP Server 1.3.29-36, 2.0.47-58, 2.2.1-2
No auth needed
Prerequisites: mod_rewrite enabled · specific RewriteRule configured · REWRITEPATH known
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by fabio/b0x · cremotewindows
https://www.exploit-db.com/exploits/3996

This exploit targets a buffer overflow vulnerability in Apache mod_rewrite on Windows systems, delivering a bind shell on port 4444. It uses a crafted HTTP GET request with shellcode to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache 2.0.58 with mod_rewrite (Windows 2003)
No auth needed
Prerequisites: Apache 2.0.58 with mod_rewrite enabled on Windows 2003 · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by axis · bashremotewindows_x86
https://www.exploit-db.com/exploits/3680

This exploit targets CVE-2006-3747, an off-by-one vulnerability in Apache mod_rewrite on Windows. It sends a crafted HTTP request with a reverse shell payload to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache HTTP Server (1.3.28-1.3.37, 2.0.46-2.0.59, 2.2.0-2.2.3)
No auth needed
Prerequisites: Apache mod_rewrite enabled · Specific RewriteRule configuration · Network access to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Jacobo Avariento · bashremotemultiple
https://www.exploit-db.com/exploits/2237

This exploit targets CVE-2006-3747, an off-by-one overflow in Apache mod_rewrite. It sends a crafted HTTP GET request with shellcode to execute a bind shell on port 30464, leveraging a specific RewriteRule configuration.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache HTTP Server 1.3.34 (mod_rewrite)
No auth needed
Prerequisites: Apache mod_rewrite with specific RewriteRule configuration · Network access to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 2 stars
by defensahacker · poc
https://github.com/defensahacker/CVE-2006-3747

This repository contains a functional exploit for CVE-2006-3747, an off-by-one buffer overflow in Apache's mod_rewrite module when processing LDAP URLs. The exploit includes a detailed technical analysis and a working shell script that triggers the vulnerability to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache HTTP Server (1.3.28-1.3.37, 2.0.46-2.0.59, 2.2.0-2.2.3)
No auth needed
Prerequisites: Apache with mod_rewrite enabled · A RewriteRule allowing user-controlled input in the remapped URL
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC GREAT
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/apache_mod_rewrite_ldap.rb

This Metasploit module exploits an off-by-one buffer overflow in Apache's mod_rewrite LDAP protocol handling (CVE-2006-3747). It targets Windows systems by sending a maliciously crafted LDAP URI to overwrite EIP and execute arbitrary payloads.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache HTTP Server 1.3.29-36, 2.0.47-58, 2.2.1-2
No auth needed
Prerequisites: RewriteEngine enabled · Specific RewriteRule configured · REWRITEPATH known
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (90)

Core 90
Core References
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3995
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28063
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/450321/100/0/threaded
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4300
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3282
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1246/references
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3264
Third Party Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_43_apache.html
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0924/references
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4015
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA08-150A.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/441487/100/0/threaded
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21266
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21307
Third Party Advisory vendor-advisory x_refsource_hp
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771
Broken Link vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1
Third Party Advisory vendor-advisory x_refsource_hp
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449
Third Party Advisory x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?uid=swg27007951
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048271.html
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23028
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21284
Third Party Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK29156
Third Party Advisory x_refsource_misc
http://kbase.redhat.com/faq/FAQ_68_8653.shtm
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22523
Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=130497311408250&w=2
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23260
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21313
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29849
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21273
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21478
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200608-01.xml
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/441485/100/0/threaded
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22368
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26329
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/445206/100/0/threaded
Broken Link vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29420
Patch, Vendor Advisory x_refsource_confirm
http://www.apache.org/dist/httpd/Announcement2.0.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19204
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21245
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4868
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30430
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4207
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:133
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21315
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/395412
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21509
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21346
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016601
Third Party Advisory x_refsource_confirm
http://docs.info.apple.com/article.html?artnum=307562
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/441526/100/200/threaded
Patch, Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1131
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21247
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3884
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1697
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/443870/100/0/threaded
Broken Link x_refsource_confirm
https://issues.rpath.com/browse/RPL-538
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22262
Third Party Advisory vendor-advisory x_refsource_openpkg
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.015-apache.html
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1312
Patch, Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1132
Third Party Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK29154
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21241
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3017
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2783
Third Party Advisory mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048267.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-328-1
Third Party Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg24013080
Broken Link vdb-entry x_refsource_osvdb
http://www.osvdb.org/27588
Mailing List, Third Party Advisory vendor-advisory x_refsource_trustix
http://lwn.net/Alerts/194228/
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22388
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21197

Scores

EPSS 0.9565
EPSS Percentile 99.9%

Details

CWE
CWE-189
Status published
Products (5)
apache/http_server 1.3.28 - 1.3.37
canonical/ubuntu_linux 5.04
canonical/ubuntu_linux 5.10
canonical/ubuntu_linux 6.06
debian/debian_linux 3.1
Published Jul 28, 2006
Tracked Since Feb 18, 2026