mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Jan 12, 2008 |
| Apache Httpd 2_2_x Mod_proxy_ftp Utf 7 Xss | — | — | Aug 16, 2010 | Jan 11, 2008 |
| Apple Osx Apache | — | Apply OS X security update 2008-002 | Dec 16, 2011 | Jan 11, 2008 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Jan 12, 2008 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Jan 11, 2008 |
| Oracle_linux | — | Upgrade httpd-manualUpgrade mod_sslUpgrade httpdUpgrade httpd-devel | Oct 16, 2024 | Jan 12, 2008 |
| Suse | — | Upgrade apache2Upgrade apache2-eventUpgrade apache2-docUpgrade apache2-workerUpgrade apache2-utilsUpgrade apache2-manualUpgrade apache2-example-pagesUpgrade apache2-develUpgrade apache2-prefork | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade apache2-mpm-workerUpgrade apache2-mpm-eventUpgrade apache2-mpm-perchildUpgrade apache2-mpm-prefork | Nov 8, 2024 | Jan 12, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub