CVE-2006-5752
medium · 4.3Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
4.3
CVSS
27.8%
EPSS (exploit prob.)
98th
EPSS percentile
2007-06-27
Published
AV:N/AC:M/Au:N/C:N/I:P/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | http_server | >= 1.3.2, < 1.3.39 |
| apache | http_server | >= 2.0.0, < 2.0.61 |
| apache | http_server | >= 2.2.0, < 2.2.6 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 6.10 |
| canonical | ubuntu_linux | 7.04 |
| fedoraproject | fedora | 7 |
| redhat | enterprise_linux_desktop | 3.0 |
| redhat | enterprise_linux_desktop | 4.0 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_eus | 4.5 |
| redhat | enterprise_linux_server | 3.0 |
| redhat | enterprise_linux_server | 4.0 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_workstation | 3.0 |
| redhat | enterprise_linux_workstation | 4.0 |
| redhat | enterprise_linux_workstation | 5.0 |
Check a specific version with /api/v1/cve/match.
References
- http://bugs.gentoo.org/show_bug.cgi?id=186219
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=245112
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795
- http://httpd.apache.org/security/vulnerabilities_13.html
- http://httpd.apache.org/security/vulnerabilities_20.html
- http://httpd.apache.org/security/vulnerabilities_22.html
- http://lists.vmware.com/pipermail/security-announce/2009/000062.html
- http://osvdb.org/37052
- http://rhn.redhat.com/errata/RHSA-2007-0534.html
- http://rhn.redhat.com/errata/RHSA-2007-0556.html
- http://secunia.com/advisories/25827
- http://secunia.com/advisories/25830
- http://secunia.com/advisories/25873
- http://secunia.com/advisories/25920
- http://secunia.com/advisories/26273
- http://secunia.com/advisories/26443
- http://secunia.com/advisories/26458
- http://secunia.com/advisories/26508
- http://secunia.com/advisories/26822
- http://secunia.com/advisories/26842
- http://secunia.com/advisories/26993
- http://secunia.com/advisories/27037
- http://secunia.com/advisories/27563
- http://secunia.com/advisories/27732
- http://secunia.com/advisories/28212
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-5752