CVE-2006-3747

Apache HTTP Server < 1.3.37 - Numeric Error

Title source: rule

Description

Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16752
exploitdb WORKING POC VERIFIED
by fabio/b0x · cremotewindows
https://www.exploit-db.com/exploits/3996
exploitdb WORKING POC VERIFIED
by axis · bashremotewindows_x86
https://www.exploit-db.com/exploits/3680
exploitdb WORKING POC VERIFIED
by Jacobo Avariento · bashremotemultiple
https://www.exploit-db.com/exploits/2237
nomisec WORKING POC 2 stars
by defensahacker · poc
https://github.com/defensahacker/CVE-2006-3747
metasploit WORKING POC GREAT
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/apache_mod_rewrite_ldap.rb

Scores

EPSS 0.9261
EPSS Percentile 99.7%

Details

CWE
CWE-189
Status published
Products (5)
apache/http_server 1.3.28 - 1.3.37
canonical/ubuntu_linux 5.04
canonical/ubuntu_linux 5.10
canonical/ubuntu_linux 6.06
debian/debian_linux 3.1
Published Jul 28, 2006
Tracked Since Feb 18, 2026