cbcvebase.
CVE-2009-3095
published 2009-09-08

CVE-2009-3095: The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server…

medium5CVSS 3.1
AVNACLAuNCNIPAN
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.

Affected

15 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.0.35 < 2.0.642.0.64
apachehttp_server>= 2.2.0 < 2.2.142.2.14
apachehttpd
applemac_os_x< 10.6.310.6.3
debianapache2< apache2 2.2.13-2 (bookworm)apache2 2.2.13-2 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
opensuseopensuse
opensuseopensuse
opensuseopensuse
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_server
suselinux_enterprise_server

CVSS provenance

nvd5.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM