漏洞描述 Apache HTTP Server是美国阿帕奇(Apache)软件基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点。 Apache HTTP Server 2.2.12版本至2.2.21版本中的mod_proxy_ajp模块中存在漏洞,该漏洞源于程序将工作节点放置于经一个较长的请求处理时间检测的错误状态下。远程攻击者可通过发送超长请求利用该漏洞造成拒绝服务(工作者耗尽)。
相关漏洞推荐 POC cl-te-http-smuggling: Basic CL.TE - HTTP request smuggling POC te-cl-http-smuggling: Basic TE.CL - HTTP Request Smuggling POC CVE-2001-0537: Cisco IOS HTTP Configuration - Authentication Bypass POC CVE-2006-1681: Cherokee HTTPD <=0.5 - Cross-Site Scripting POC CVE-2014-2323: Lighttpd 1.4.34 SQL Injection and Path Traversal POC CVE-2017-15715: Apache httpd <=2.4.29 - Arbitrary File Upload POC CVE-2018-16133: Cybrotech CyBroHttpServer 1.0.3 - Local File Inclusion POC CVE-2018-18778: ACME mini_httpd <1.30 - Local File Inclusion POC CVE-2019-10092: Apache HTTP Server <=2.4.39 - HTML Injection/Partial Cross-Site Scripting POC CVE-2019-10098: Apache HTTP server v2.4.0 to v2.4.39 - Open Redirect POC CVE-2020-11984: Apache HTTP Server - Remote Code Execution POC CVE-2024-23334: aiohttp - Directory Traversal POC CVE-2024-23692: Rejetto HTTP File Server - Template injection