S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2016-4975 Scanner

CVE-2016-4975 scanner - CRLF Injection vulnerability in Apache Software Foundation Apache HTTP Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2016-4975
6.1
CVSS

Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache HTTP Serverby Apache Software Foundation
Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23)
Updated Aug 22, 2026View on NVD →
Detail

Apache HTTP Server is a widely used open-source web server software that is designed to provide a secure and efficient environment for serving web content. It is available on most operating systems and is used by a large number of websites and web applications worldwide. It is easy to use, free to download, and can be customized to suit the needs of individual users. The Apache HTTP Server is highly reliable and scalable, making it a popular choice for web developers and users.

CVE-2016-4975 is a security vulnerability that was detected in Apache HTTP Server version 2.4.1 to 2.4.23 and 2.2.0 to 2.2.31. This particular vulnerability allowed for CRLF (Carriage Return Line Feed) injection, which made it possible for an attacker to insert arbitrary headers into the response of a web application. This, in turn, could enable HTTP response splitting attacks that might result in the stealing of sensitive data or the hijacking of a user's session.

When this vulnerability is exploited, an attacker can send manipulated HTTP headers that would allow them to insert arbitrary newlines or headers into the response of the server. This could lead to JavaScript injection, cookie theft or session hijacking, which would seriously compromise the security of the website. In the worst-case scenario, an attacker could gain complete control of the system and access confidential data.

In conclusion, it is essential to ensure that all systems and software are updated regularly to prevent vulnerabilities such as CVE-2016-4975. With the pro features of the s4e.io platform, web developers and users can gain instant access to information about vulnerabilities in their digital assets. They can proactively protect their website or web application by promptly addressing any vulnerabilities that are detected, thereby helping to minimize the risk of security breaches.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Update Apache HTTP Server to version 2.4.25 or version 2.2.32, which includes a fix for the vulnerability.
  • Scan the server using a vulnerability scanner to ensure that all software is up to date and secure.
  • Implement strict input validation to ensure that user input is not being used to inject arbitrary headers.
  • Configure firewalls to block traffic from suspicious IP addresses

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2016-4975 scanner - CRLF Injection vulnerability in Apache Software Foundation Apache HTTP Server | S4E