CVE-2010-2227
Apache Tomcat 5.5.0-5.5.29, 6.0.0-6.0.27, 7.0.0 beta - Denial of Service via Invalid Transfer-Encoding Header
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2227.
PoCs published by Steve Jones, including Metasploit module auxiliary/dos/http/apache_tomcat_transfer_encoding.
AI-analyzed exploit summary This Metasploit module exploits a vulnerability in Apache Tomcat (CVE-2010-2227) by sending malformed Transfer-Encoding headers to cause a denial of service (DoS) or information disclosure. It sends multiple crafted HTTP POST requests with an invalid Transfer-Encoding header and an oversized Content-Length to trigger the vulnerability.
Description
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."
Exploits (1)
This Metasploit module exploits a vulnerability in Apache Tomcat (CVE-2010-2227) by sending malformed Transfer-Encoding headers to cause a denial of service (DoS) or information disclosure. It sends multiple crafted HTTP POST requests with an invalid Transfer-Encoding header and an oversized Content-Length to trigger the vulnerability.