Script http-vuln-cve2011-3368

Script types: portrule
Categories: intrusive, vuln

Script Summary

Tests for the CVE-2011-3368 (Reverse Proxy Bypass) vulnerability in Apache HTTP server's reverse proxy mode. The script will run 3 tests:

  • the loopback test, with 3 payloads to handle different rewrite rules
  • the internal hosts test. According to Contextis, we expect a delay before a server error.
  • The external website test. This does not mean that you can reach a LAN ip, but this is a relevant issue anyway.


Script Arguments


sets the path prefix (directory) to check for the vulnerability.


Example Usage

nmap --script http-vuln-cve2011-3368 <targets>

Script Output

80/tcp open  http
| http-vuln-cve2011-3368:
|   Apache mod_proxy Reverse Proxy Security Bypass
|     State: VULNERABLE
|     IDs:  CVE:CVE-2011-3368  BID:49957
|     Description:
|       An exposure was reported affecting the use of Apache HTTP Server in
|       reverse proxy mode. The exposure could inadvertently expose internal
|       servers to remote users who send carefully crafted requests.
|     Disclosure date: 2011-10-05
|     Extra information:
|       Proxy allows requests to external websites
|     References:



  • Ange Gutek
  • Patrik Karlsson

License: Same as Nmap--See