CVE-2006-3747
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Apache mod_rewrite (Windows x86) - Off-by-One Remote Overflow
by axis · Apr 7, 2007
Apache mod_rewrite - LDAP protocol Buffer Overflow (Metasploit)
by Metasploit · Feb 15, 2010
Apache < 1.3.37/2.0.59/2.2.3 mod_rewrite - Remote Overflow
by Jacobo Avariento · Aug 21, 2006
Apache 2.0.58 mod_rewrite (Windows 2003) - Remote Overflow
by fabio/b0x · May 26, 2007
Frequently Asked Questions
Is CVE-2006-3747 in your stack?
O3 detects CVE-2006-3747 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.