cbcvebase.
CVE-2009-3095
published 2009-09-08

CVE-2009-3095: The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server…

PriorityP338medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
12.56%
95.8th percentile
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.

Affected

15 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.0.35 < 2.0.642.0.64
apachehttp_server>= 2.2.0 < 2.2.142.2.14
apachehttpd
applemac_os_x< 10.6.310.6.3
debianapache2< apache2 2.2.13-2 (bookworm)apache2 2.2.13-2 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
opensuseopensuse
opensuseopensuse
opensuseopensuse
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_server
suselinux_enterprise_server

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_apache5.0LOW
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.