← back
CVE-2011-4317

CVE-2011-4317

35Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 60%
from disclosure to weapon0 days
Published on NVDNov 30
1st PoCNov 24
exploitation probability
60%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.