Логотип exploitDog
bind:"CVE-2012-2687" OR bind:"CVE-2008-0455" OR bind:"CVE-2012-4557"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2012-2687" OR bind:"CVE-2008-0455" OR bind:"CVE-2012-4557"

Количество 17

Количество 17

oracle-oval логотип

ELSA-2013-0512

больше 12 лет назад

ELSA-2013-0512: httpd security, bug fix, and enhancement update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2013-0130

больше 12 лет назад

ELSA-2013-0130: httpd security, bug fix, and enhancement update (LOW)

EPSS: Низкий
ubuntu логотип

CVE-2012-2687

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2012-2687

около 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2012-2687

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2012-2687

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the make_varian ...

CVSS2: 2.6
EPSS: Низкий
github логотип

GHSA-8v5x-5rvv-5j4v

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.

EPSS: Низкий
ubuntu логотип

CVE-2012-4557

больше 12 лет назад

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2012-4557

больше 13 лет назад

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.

CVSS2: 2.6
EPSS: Средний
nvd логотип

CVE-2012-4557

больше 12 лет назад

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2012-4557

больше 12 лет назад

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2. ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2008-0455

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2008-0455

около 13 лет назад

Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.

CVSS2: 2.6
EPSS: Средний
nvd логотип

CVE-2008-0455

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2008-0455

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in the mod_negotiation module ...

CVSS2: 4.3
EPSS: Средний
github логотип

GHSA-9p9q-h6h7-37g9

больше 3 лет назад

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.

EPSS: Средний
github логотип

GHSA-3rhp-x8rm-9rvr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2013-0512

ELSA-2013-0512: httpd security, bug fix, and enhancement update (LOW)

больше 12 лет назад
oracle-oval логотип
ELSA-2013-0130

ELSA-2013-0130: httpd security, bug fix, and enhancement update (LOW)

больше 12 лет назад
ubuntu логотип
CVE-2012-2687

Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.

CVSS2: 2.6
8%
Низкий
почти 13 лет назад
redhat логотип
CVE-2012-2687

Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.

CVSS2: 2.6
8%
Низкий
около 13 лет назад
nvd логотип
CVE-2012-2687

Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.

CVSS2: 2.6
8%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-2687

Multiple cross-site scripting (XSS) vulnerabilities in the make_varian ...

CVSS2: 2.6
8%
Низкий
почти 13 лет назад
github логотип
GHSA-8v5x-5rvv-5j4v

Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.

8%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2012-4557

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.

CVSS2: 5
23%
Средний
больше 12 лет назад
redhat логотип
CVE-2012-4557

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.

CVSS2: 2.6
23%
Средний
больше 13 лет назад
nvd логотип
CVE-2012-4557

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.

CVSS2: 5
23%
Средний
больше 12 лет назад
debian логотип
CVE-2012-4557

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2. ...

CVSS2: 5
23%
Средний
больше 12 лет назад
ubuntu логотип
CVE-2008-0455

Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.

CVSS2: 4.3
32%
Средний
больше 17 лет назад
redhat логотип
CVE-2008-0455

Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.

CVSS2: 2.6
32%
Средний
около 13 лет назад
nvd логотип
CVE-2008-0455

Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.

CVSS2: 4.3
32%
Средний
больше 17 лет назад
debian логотип
CVE-2008-0455

Cross-site scripting (XSS) vulnerability in the mod_negotiation module ...

CVSS2: 4.3
32%
Средний
больше 17 лет назад
github логотип
GHSA-9p9q-h6h7-37g9

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.

23%
Средний
больше 3 лет назад
github логотип
GHSA-3rhp-x8rm-9rvr

Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.

32%
Средний
больше 3 лет назад

Уязвимостей на страницу