mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 02:45:46 +02:00
1.6 KiB
1.6 KiB
CVE-2010-0408
Description
The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
POC
Reference
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829
- http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9935
Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/DButter/whitehat_public
- https://github.com/Dokukin1/Metasploitable
- https://github.com/GiJ03/ReconScan
- https://github.com/Iknowmyname/Nmap-Scans-M2
- https://github.com/NikulinMS/13-01-hw
- https://github.com/RoliSoft/ReconScan
- https://github.com/SecureAxom/strike
- https://github.com/Zhivarev/13-01-hw
- https://github.com/adamziaja/vulnerability-check
- https://github.com/issdp/test
- https://github.com/matoweb/Enumeration-Script
- https://github.com/smabramov/Vulnerabilities-and-attacks-on-information-systems
- https://github.com/xxehacker/strike
- https://github.com/zzzWTF/db-13-01