7.5
CVSSv2

CVE-2007-6258

Published: 19/02/2008 Updated: 03/02/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and previous versions Apache module allow remote malicious users to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache mod jk 2.0

apache mod jk 2.0.1

apache mod jk 2.0.2

apache mod jk 2.0.3_dev

f5 big-ip 9.2.3.30

Exploits

/* ** ** Fedora Core 6,7,8 (exec-shield) based ** Apache Tomcat Connector jk2-202(mod_jk2) remote overflow exploit ** by INetCop Security ** ** Advanced exploitation in exec-shield (Fedora Core case study) ** URL: wwwmilw0rmcom/papers/151 ** ** IOActive Security Advisory: ** wwwsecurityfocuscom/archive/1/487983 ** ** Heretic2(he ...