The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Sep 8, 2009 |
| Apache Httpd 2_0_x Mod_proxy_ftp Ftp Command Injection | — | — | Aug 16, 2010 | Sep 8, 2009 |
| Apache Httpd 2_2_x Mod_proxy_ftp Ftp Command Injection | — | — | Aug 16, 2010 | Sep 8, 2009 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2010-002 | Dec 16, 2011 | Sep 8, 2009 |
| Centos_linux | — | Upgrade httpdUpgrade mod_sslUpgrade httpd-manualUpgrade httpd-suexecUpgrade httpd-devel | Dec 1, 2016 | Sep 8, 2009 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Sep 8, 2009 |
| Oracle_linux | — | Upgrade httpdUpgrade httpd-develUpgrade mod_sslUpgrade httpd-manual | Oct 16, 2024 | Sep 8, 2009 |
| Suse | — | Upgrade apache2-manualUpgrade apache2Upgrade apache2-develUpgrade apache2-example-pagesUpgrade apache2-preforkUpgrade apache2-eventUpgrade apache2-workerUpgrade apache2-utilsUpgrade apache2-doc | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade apache2-commonUpgrade apache2.2-common | Nov 8, 2024 | Sep 8, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub