CVE-2006-3747 is an off-by-one error in the mod_rewrite module of Apache HTTP Server versions 1.3 (from 1.3.28), 2.0 (before 2.0.59), and 2.2, affecting various Linux distributions. This vulnerability, triggered by crafted URLs with specific rewrite rules, can lead to a denial of service and potentially arbitrary code execution. With a CVSS score of 7.6, it is considered highly severe due to its network attack vector, high impact on confidentiality, integrity, and availability, despite requiring high attack complexity. Although not on the KEV catalog, exploit code is publicly available via Metasploit and ExploitDB, indicating a high potential for exploitation, yet it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.3.28, < 1.3.37CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
>= 2.0.46, < 2.0.59CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
>= 2.2.0, < 2.2.3CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
5.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:5.04:*:*:*:*:*:*:* | ||
5.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.