Apache httpd是美国阿帕奇(Apache)软件基金会的一款专为现代操作系统开发和维护的开源HTTP服务器。 Apache httpd 2.4.0版本至2.4.29版本中存在安全漏洞。攻击者可通过向目标系统发送特制的文件利用该漏洞绕过安全限制。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Apache Software Foundation | Apache HTTP Server | 2.4.0 to 2.4.29 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | None | https://github.com/whisp1830/CVE-2017-15715 | POC详情 |
| 2 | Apache httpd 2.4.0 to 2.4.29 is susceptible to arbitrary file upload vulnerabilities via the expression specified in <FilesMatch>, which could match '$' to a newline character in a malicious filename rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are externally blocked, but only by matching the trailing portion of the filename. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-15715.yaml | POC详情 |
| 3 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Apache%20HTTPd%20%E6%8D%A2%E8%A1%8C%E8%A7%A3%E6%9E%90%E6%BC%8F%E6%B4%9E%20CVE-2017-15715.md | POC详情 |
| 4 | https://github.com/vulhub/vulhub/blob/master/httpd/CVE-2017-15715/README.md | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2017-15710 | Apache httpd 安全漏洞 | |
| CVE-2018-1283 | Apache httpd 输入验证错误漏洞 | |
| CVE-2018-1301 | Apache HTTP Server 安全漏洞 | |
| CVE-2018-1302 | Apache HTTP Server 安全漏洞 | |
| CVE-2018-1303 | Apache HTTP Server 缓冲区错误漏洞 | |
| CVE-2018-1312 | Apache httpd mod_auth_digest模块安全漏洞 |
暂无评论