Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点。 Apache HTTP Server 2.4.59及之前版本存在安全漏洞,该漏洞源于输出转义不当,允许攻击者将URL映射无法通过任何URL直接访问的文件系统位置,从而导致代码执行或源代码泄露。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Apache Software Foundation | Apache HTTP Server | 2.4.0 ~ 2.4.59 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | None | https://github.com/p0in7s/CVE-2024-38475 | POC详情 |
| 2 | exploit CVE-2024-38475(mod_rewrite weakness with filesystem path matching) | https://github.com/soltanali0/CVE-2024-38475 | POC详情 |
| 3 | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected. Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-38475.yaml | POC详情 |
| 4 | CVE-2024-38475 Scanner using FFUF + Seclists | https://github.com/syaifulandy/CVE-2024-38475 | POC详情 |
| 5 | None | https://github.com/abrewer251/CVE-2024-38475_SonicBoom_Apache_URL_Traversal_PoC | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2024-36387 | Apache HTTP Server 代码问题漏洞 | |
| CVE-2024-38472 | Apache HTTP Server 安全漏洞 | |
| CVE-2024-38473 | Apache HTTP Server 安全漏洞 | |
| CVE-2024-38474 | Apache HTTP Server 安全漏洞 | |
| CVE-2024-38476 | Apache HTTP Server 安全漏洞 | |
| CVE-2024-38477 | Apache HTTP Server 代码问题漏洞 | |
| CVE-2024-39573 | Apache HTTP Server 输入验证错误漏洞 |
暂无评论