Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Apache | — | Apply OS X security update 2008-003 | Dec 16, 2011 | Sep 13, 2007 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Sep 14, 2007 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Sep 13, 2007 |
| Hpux | — | Update hpuxwsAPCH32.AUTH_LDAP2 to the latest versionUpdate hpuxwsAPACHE.PHP to the latest versionUpdate hpuxwsAPCH32.MOD_JK to the latest versionUpdate hpuxwsAPACHE.MOD_PERL2 to the latest versionUpdate hpuxwsAPCH32.PHP2 to the latest versionUpdate hpuxwsAPCH32.MOD_PERL2 to the latest versionUpdate hpuxwsAPCH32.MOD_JK2 to the latest versionUpdate hpuxwsAPCH32.APACHE2 to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP to the latest versionUpdate hpuxwsAPACHE.WEBPROXY to the latest versionUpdate hpuxwsAPCH32.APACHE to the latest versionUpdate hpuxwsAPCH32.PHP to the latest versionUpdate hpuxwsAPCH32.WEBPROXY to the latest versionUpdate hpuxwsAPACHE.MOD_JK2 to the latest versionUpdate hpuxwsAPCH32.MOD_PERL to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP2 to the latest versionUpdate hpuxwsAPACHE.APACHE2 to the latest versionUpdate hpuxwsAPACHE.PHP2 to the latest versionUpdate hpuxwsAPACHE.APACHE to the latest versionUpdate hpuxwsAPACHE.MOD_PERL to the latest versionUpdate hpuxwsAPCH32.AUTH_LDAP to the latest versionUpdate hpuxwsAPACHE.MOD_JK to the latest version | Aug 11, 2017 | Sep 13, 2007 |
| Oracle_linux | — | Upgrade httpd-develUpgrade httpdUpgrade mod_sslUpgrade httpd-manual | Oct 16, 2024 | Sep 14, 2007 |
| Suse | — | Upgrade apache2Upgrade apache2-example-pagesUpgrade apache2-workerUpgrade apache2-preforkUpgrade apache2-develUpgrade apache2-manualUpgrade apache2-docUpgrade apache2-eventUpgrade apache2-utils | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade apache2-mpm-perchildUpgrade apache2-mpm-workerUpgrade apache2-mpm-preforkUpgrade apache2-mpm-event | Nov 8, 2024 | Sep 14, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub