mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-14 15:08:03 +02:00
32 lines
1.5 KiB
Markdown
32 lines
1.5 KiB
Markdown
### [CVE-2008-2364](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2364)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html
|
|
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9577
|
|
|
|
#### Github
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/DButter/whitehat_public
|
|
- https://github.com/Dokukin1/Metasploitable
|
|
- https://github.com/GiJ03/ReconScan
|
|
- https://github.com/Iknowmyname/Nmap-Scans-M2
|
|
- https://github.com/Live-Hack-CVE/CVE-2008-2364
|
|
- https://github.com/NikulinMS/13-01-hw
|
|
- https://github.com/RoliSoft/ReconScan
|
|
- https://github.com/Zhivarev/13-01-hw
|
|
- https://github.com/issdp/test
|
|
- https://github.com/kasem545/vulnsearch
|
|
- https://github.com/matoweb/Enumeration-Script
|
|
- https://github.com/smabramov/Vulnerabilities-and-attacks-on-information-systems
|
|
- https://github.com/zzzWTF/db-13-01
|
|
|