This alert was generated using only banner information. It may be a false positive.
By sending a specially crafted request followed by a reset packet it is possible to trigger a vulnerability in Apache mod_isapi that will unload the target ISAPI module from memory. However function pointers still remain in memory and are called when published ISAPI functions are referenced. This results in a dangling pointer vulnerability.
Affected Apache versions (up to 2.2.14 on Windows platform).
- Upgrade Apache to the latest version.
- Drupal Core 8.x.x Remote Code Execution (8.0.0 - 8.3.8)
- WordPress Plugin Mail On Update Cross-Site Request Forgery (5.1.0)
- WordPress Plugin FormCraft-Contact Form Builder Cross-Site Request Forgery (1.2.1)
- WordPress Plugin Answer My Question SQL Injection (1.3)
- WordPress Plugin Flamingo Code Injection (1.1)