Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Jan 8, 2008 |
| Apple Osx Apache | — | Apply OS X security update 2008-002 | Dec 16, 2011 | Jan 8, 2008 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Jan 8, 2008 |
| Oracle_linux | — | Upgrade httpdUpgrade httpd-develUpgrade mod_sslUpgrade httpd-manual | Oct 16, 2024 | Jan 8, 2008 |
| Suse | — | Upgrade apache2-example-pagesUpgrade apache2-develUpgrade apache2Upgrade apache2-manualUpgrade apache2-eventUpgrade apache2-preforkUpgrade apache2-utilsUpgrade apache2-docUpgrade apache2-worker | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade apache2-mpm-preforkUpgrade apache2-mpm-workerUpgrade apache2-mpm-perchildUpgrade apache2-mpm-event | Nov 8, 2024 | Jan 8, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub