CVE-2007-4465
medium · 6.1Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
6.1
CVSS
26.2%
EPSS (exploit prob.)
98th
EPSS percentile
2007-09-14
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | http_server | >= 2.0.0, < 2.0.61 |
| apache | http_server | >= 2.2.0, < 2.2.6 |
Check a specific version with /api/v1/cve/match.
References
- http://bugs.gentoo.org/show_bug.cgi?id=186219
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
- http://marc.info/?l=bugtraq&m=124654546101607&w=2
- http://marc.info/?l=bugtraq&m=125631037611762&w=2
- http://secunia.com/advisories/26842
- http://secunia.com/advisories/26952
- http://secunia.com/advisories/27563
- http://secunia.com/advisories/27732
- http://secunia.com/advisories/28467
- http://secunia.com/advisories/28471
- http://secunia.com/advisories/28607
- http://secunia.com/advisories/28749
- http://secunia.com/advisories/30430
- http://secunia.com/advisories/31651
- http://secunia.com/advisories/33105
- http://secunia.com/advisories/35650
- http://security.gentoo.org/glsa/glsa-200711-06.xml
- http://securityreason.com/achievement_securityalert/46
- http://securityreason.com/securityalert/3113
- http://securitytracker.com/id?1019194
- http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm
- http://www.apache.org/dist/httpd/CHANGES_2.2.6
- http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:014
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-4465