← All CVEs

CVE-2006-2769

medium · 5

The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriage return (\r) after the URL and before the HTTP declaration.

5
CVSS
10.8%
EPSS (exploit prob.)
96th
EPSS percentile
2006-06-02
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
sourcefiresnort2.4
sourcefiresnort2.4.1
sourcefiresnort2.4.2
sourcefiresnort2.4.3
sourcefiresnort2.4.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-2769