QID 730846
Date Published: 2023-07-24
QID 730846: Apache HTTP Server CRLF Injection Vulnerability (CVE-2016-4975)
Apache HTTP Server is an HTTP web server application.
Affected Versions:
Apache HTTP Server versions 2.4.1-2.4.23
Apache HTTP Server versions 2.2.0-2.2.31
QID Detection Logic:(Unauthenticated)
This QID checks for server banner to detect if the target is running vulnerable version of apache httpd.
Successful exploitation of this vulnerability may allow an attacker to launch HTTP response splitting attacks for sites which use mod_userdir.
Solution
Vendor References
- Apache HTTP Server 2.2.32 -
httpd.apache.org/security/vulnerabilities_22.html#CVE-2016-4975 - Apache HTTP Server 2.4.25 -
httpd.apache.org/security/vulnerabilities_24.html#CVE-2016-4975
CVEs related to QID 730846
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache HTTP Server 2.2.32 |
|
||
| Apache HTTP Server 2.4.25 |
|