QID 730846

Date Published: 2023-07-24

QID 730846: Apache HTTP Server CRLF Injection Vulnerability (CVE-2016-4975)

Apache HTTP Server is an HTTP web server application.

Affected Versions:
Apache HTTP Server versions 2.4.1-2.4.23
Apache HTTP Server versions 2.2.0-2.2.31

QID Detection Logic:(Unauthenticated)
This QID checks for server banner to detect if the target is running vulnerable version of apache httpd.

Successful exploitation of this vulnerability may allow an attacker to launch HTTP response splitting attacks for sites which use mod_userdir.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to update latest Apache httpd 2.4.25 and 2.2.32 for 2.4.x and 2.2.x versions respectively.
    For more information, visit here.
    For more information, visit here.

    CVEs related to QID 730846

    Software Advisories
    Advisory ID Software Component Link
    Apache HTTP Server 2.2.32 URL Logo httpd.apache.org/security/vulnerabilities_22.html#CVE-2016-4975
    Apache HTTP Server 2.4.25 URL Logo httpd.apache.org/security/vulnerabilities_24.html#CVE-2016-4975