Vulnerability record · CVE-2006-3747 · published 28 July 2006
CVE-2006-3747: Apache mod_rewrite LDAP scheme off-by-one allows crash and possible code execution
Apache · Http Server
An off-by-one error in the LDAP scheme handling of Apache's mod_rewrite affects Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2 when RewriteEngine is enabled. Crafted URLs processed by certain rewrite rules can crash the server and may allow arbitrary code execution. The flaw matters because mod_rewrite is widely deployed and reachable by unauthenticated remote clients.
Description
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
AV:N/AC:H/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote unauthenticated flaw with a high CVSS score and very high EPSS probability, though exploitation requires specific rewrite rule configurations and no KEV listing exists.
What it is
An off-by-one error in the LDAP scheme handling of Apache's mod_rewrite affects Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2 when RewriteEngine is enabled. Crafted URLs processed by certain rewrite rules can crash the server and may allow arbitrary code execution. The flaw matters because mod_rewrite is widely deployed and reachable by unauthenticated remote clients.
Impact
An attacker can cause a denial of service by crashing the Apache process and may be able to execute arbitrary code in the context of the web server.
Attack surface
Reached remotely over the network via crafted HTTP URLs handled by mod_rewrite rules that use the LDAP scheme; no authentication is required and no user interaction is indicated by the AV:N/Au:N vector.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.96578, 99.88th percentile), and references include full-disclosure mailing list posts, indicating public discussion of the flaw.
What to do
- Upgrade Apache to a fixed release (2.0.59 or later for the 2.0 branch, or a patched 2.2/1.3 build) as the first action.
- If patching is not immediately possible, disable RewriteEngine or remove rewrite rules that handle the LDAP scheme.
- Apply vendor patches from Apache, Canonical, Debian, Red Hat, HP or Apple as applicable to your distribution.
- Restrict or monitor external access to web servers running affected Apache versions until patched.
Detection
- Review Apache error and access logs for crashes or abnormal requests to URLs matching rewrite rules that use the LDAP scheme.
- Monitor for repeated Apache process crashes or restarts correlated with crafted URL patterns.
- Inventory Apache versions and confirm which hosts have RewriteEngine enabled with LDAP-related rewrite rules.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-3747 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-3747), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.