vendor:
Apache HTTP Server
by:
Unknown
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Apache HTTP Server
Affected Version From: 2.0.46
Affected Version To: 2.2.2004
Patch Exists: YES
Related CWE: CVE-2007-6203
CPE: a:apache:http_server:2.0.46
Metasploit:
https://www.rapid7.com/db/vulnerabilities/apache-httpd-cve-2007-6203/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2007-6203/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2007-6203/, https://www.rapid7.com/db/vulnerabilities/apple-osx-apache-cve-2007-6203/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2007-6203/
Platforms Tested:
2007
Apache Cross-Site Scripting Vulnerability
Apache is prone to a cross-site scripting weakness when handling HTTP request methods that result in 413 HTTP errors. An attacker may exploit this issue to steal cookie-based authentication credentials and launch other attacks.
Mitigation:
Apply the necessary patches or updates provided by the Apache Foundation. Additionally, implement input validation and output encoding to prevent cross-site scripting vulnerabilities.