cbcvebase.
CVE-2007-6750
published 2011-12-27

CVE-2007-6750: The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by…

PriorityP342medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
71.63%
99.4th percentile
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.

Affected

117 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server<= 2.2.14
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server

Detection & IOCsextracted from sources · hover to see the quote

commandnmap --script vuln -p 80 <target>
commandnmap --script=vuln <target>
  • Nmap http-slowloris-check script detects CVE-2007-6750 (Slowloris DOS) by identifying servers likely vulnerable to partial HTTP request exhaustion attacks.
  • Apache HTTP Server versions before 2.2.15 lack mod_reqtimeout, which is the primary mitigation; absence of this module is a key indicator of vulnerability.
  • ·Red Hat Enterprise Linux 5 and 6 ship httpd with mod_reqtimeout enabled, which mitigates the vulnerability; RHEL 4 remains unmitigated.
  • ·Both Apache HTTP Server 1.x and 2.x branches are affected, not just a single major version.

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.