Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-3918

Опубликовано: 28 июл. 2006
Источник: ubuntu
Приоритет: low
EPSS Критический
CVSS2: 4.3

Описание

http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

edgy

released

1.3.34-4ubuntu1
feisty

released

1.3.34-4ubuntu1
gutsy

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

2.0.55-4ubuntu2.3
devel

released

2.2.4-3
edgy

released

2.0.55-4ubuntu4.1
feisty

released

2.2.3-3.2ubuntu0.1
gutsy

released

2.2.4-3
hardy

released

2.2.4-3
intrepid

released

2.2.4-3
jaunty

released

2.2.4-3
karmic

released

2.2.4-3
upstream

needs-triage

Показывать по

EPSS

Процентиль: 100%
0.90108
Критический

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 19 лет назад

http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.

nvd
около 19 лет назад

http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.

debian
около 19 лет назад

http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 bef ...

github
больше 3 лет назад

http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.

EPSS

Процентиль: 100%
0.90108
Критический

4.3 Medium

CVSS2