Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-4465

Опубликовано: 14 сент. 2007
Источник: debian

Описание

Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apacheremovedpackage
apache2fixed2.2.6-1package
apacheno-dsasargepackage
apache2no-dsasargepackage

Примечания

  • This is really a browser bug, see CVE-2006-5152. But still unfixed in MSIE.

  • Etch's default configuration not vulnerable due to AddDefaultCharset,

  • but many users change this.

  • The apache2 fix is actually a workaround. It will not be applied to apache 1.3.

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 18 лет назад

Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.

redhat
почти 18 лет назад

Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.

CVSS3: 6.1
nvd
почти 18 лет назад

Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.

CVSS3: 6.1
github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.

oracle-oval
больше 17 лет назад

ELSA-2008-0008: Moderate: httpd security update (MODERATE)