7.5
CVSSv2

CVE-2007-6258

Published: 19/02/2008 Updated: 03/02/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and previous versions Apache module allow remote malicious users to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache mod jk 2.0

apache mod jk 2.0.1

apache mod jk 2.0.2

apache mod jk 2.0.3 dev

f5 big-ip 9.2.3.30

Exploits

/* ** ** Fedora Core 6,7,8 (exec-shield) based ** Apache Tomcat Connector jk2-202(mod_jk2) remote overflow exploit ** by INetCop Security ** ** Advanced exploitation in exec-shield (Fedora Core case study) ** URL: wwwmilw0rmcom/papers/151 ** ** IOActive Security Advisory: ** wwwsecurityfocuscom/archive/1/487983 ** ** Heretic2(he ...