Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
CVSS Details
- CVSS 3.1 Base Score: 5.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade httpd-toolsUpgrade mod_sslUpgrade httpdUpgrade httpd-develUpgrade httpd-manual | Dec 1, 2016 | Jan 24, 2008 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Jan 25, 2008 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 1, 2015 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Jan 24, 2008 |
| Oracle_linux | — | Upgrade httpd-manualUpgrade httpd-toolsUpgrade httpd-develUpgrade httpdUpgrade mod_ssl | Oct 16, 2024 | Jan 25, 2008 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Jun 13, 2012 |
| Suse | — | Upgrade apache2-preforkUpgrade apache2-docUpgrade apache2-example-pagesUpgrade apache2-workerUpgrade apache2Upgrade apache2-utils | Dec 12, 2013 | Jan 24, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub