← All CVEs

CVE-2008-0005

medium · 4.3

mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.

4.3
CVSS
14.7%
EPSS (exploit prob.)
97th
EPSS percentile
2008-01-12
Published

AV:N/AC:M/Au:N/C:N/I:P/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
apachehttp_server>= 2.0.35, < 2.0.63
apachehttp_server>= 2.2.0, < 2.2.8
fedoraprojectfedora7
fedoraprojectfedora8
canonicalubuntu_linux6.06
canonicalubuntu_linux6.10
canonicalubuntu_linux7.04
canonicalubuntu_linux7.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-0005