May 22, 2012, 09:44:46 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: THC is up and running !
 

 
advertisement:

Pages: [1]
  Print  
Author Topic: RSS: Apache HTTP Server mod_proxy Reverse Proxy HTTP 0.9 Information Disclosure  (Read 20 times)
zomgwtfbbq
Challenge Coder
Administrator
Hero Member
*****

Karma: +31340/-1
Posts: I am a geek!!


thc title: thc elite
thc points: 3315
challenges: (69/83)

View Profile
« on: February 09, 2012, 08:45:52 PM »
Share on FacebookFacebook Share

Apache HTTP Server mod_proxy Reverse Proxy HTTP 0.9 Information Disclosure


Synopsis :

The web server running on the remote host has an information
disclosure vulnerability.

Description :

The version of Apache HTTP Server running on the remote host has an
information disclosure vulnerability. When configured as a reverse
proxy, improper use of the RewriteRule and ProxyPassMatch directives
could cause the web server to proxy requests to arbitrary hosts. This
could allow a remote attacker to indirectly send requests to intranet
servers by making specially crafted HTTP 0.9 requests.

This vulnerability only affects versions 2.2.x before 2.2.18 that have
backported the fix for CVE-2011-3368.

See also :


only registered users with at least 25 hack challenge points can see links:
click here in order to visit the hack challenges
https://bugzilla.novell.com/show_bug.cgi?id=722545#c15


only registered users with at least 25 hack challenge points can see links:
click here in order to visit the hack challenges
http://article.gmane.org/gmane.comp.apache.devel/45983


only registered users with at least 25 hack challenge points can see links:
click here in order to visit the hack challenges
http://svn.apache.org/viewvc?view=revision&revision=1188745


Solution :

Contact the distro/vendor for the latest update of Apache httpd.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Temporal Score : 4.1
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true



original thread:
only registered users with at least 25 hack challenge points can see links:
click here in order to visit the hack challenges
http://www.nessus.org/plugins/index.php?view=single&id=57875
Logged


only registered users with at least 25 hack challenge points can see links:
  click here in order to visit the hack challenges


Ook al ben ik een slet toch houdt ik van je..
Pages: [1]
  Print  
 
Jump to:  


SMF Board hacked and modded by zomgwtfbekjam aka Rembo from Tools & Design