vendor:
mod_gzip
by:
xCrZx
9,3
CVSS
HIGH
mod_gzip (debug_mode)
N/A
CWE
Product Name: mod_gzip
Affected Version From: 1.2.26.1a
Affected Version To: 1.3.19.2a
Patch Exists: YES
Related CWE: N/A
CPE: a:mod_gzip:mod_gzip:1.2.26.1a
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, BSD
2003
Remote Exploit for mod_gzip (debug_mode) [Linux/*BSD]
This is a remote exploit for mod_gzip (debug_mode) on Linux/*BSD systems. It can be used in single mode or brute mode. In single mode, it connects to the target on port 80 and tries to connect to port 2003. In brute mode, it uses a step of 1000 and tries to connect to port 2003. If successful, it will give a shell access to the target.
Mitigation:
Disable debug_mode in mod_gzip, upgrade to the latest version of mod_gzip, or use an alternative solution.