Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-5752

Опубликовано: 27 июн. 2007
Источник: ubuntu
Приоритет: untriaged
EPSS Средний
CVSS2: 4.3

Описание

Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.

РелизСтатусПримечание
dapper

released

2.0.55-4ubuntu2.2
devel

released

2.2.4-3
edgy

released

2.0.55-4ubuntu4.1
feisty

released

2.2.3-3.2ubuntu0.1
upstream

needs-triage

Показывать по

EPSS

Процентиль: 94%
0.15794
Средний

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 18 лет назад

Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.

nvd
почти 18 лет назад

Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.

debian
почти 18 лет назад

Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_st ...

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.

oracle-oval
почти 18 лет назад

ELSA-2007-0556: Moderate: httpd security update (MODERATE)

EPSS

Процентиль: 94%
0.15794
Средний

4.3 Medium

CVSS2