CVE-2024-38474
CRITICALApache HTTP Server < 2.4.60 - Script Execution via mod_rewrite Substitution Encoding Issue
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-38474. PoCs published by mrmtwoj.
AI-analyzed exploit summary This repository contains a Python-based scanner that tests for multiple Apache HTTP Server vulnerabilities, including CVE-2024-38474, by sending crafted HTTP requests to detect potential misconfigurations or weaknesses. It does not include exploit code for achieving RCE or other offensive actions but checks for vulnerable endpoints and response patterns.
Description
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
Exploits (1)
This repository contains a Python-based scanner that tests for multiple Apache HTTP Server vulnerabilities, including CVE-2024-38474, by sending crafted HTTP requests to detect potential misconfigurations or weaknesses. It does not include exploit code for achieving RCE or other offensive actions but checks for vulnerable endpoints and response patterns.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H