PT-2002-2150 · Apache · Apache Mod Ssl
Publicado
2002-11-04
·
Atualizado
2008-09-05
·
CVE-2002-1157
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Apache mod ssl module version 2.8.9 and earlier
Description:
A cross-site scripting issue exists in the mod ssl Apache module. This occurs when UseCanonicalName is off and wildcard DNS is enabled, allowing remote attackers to execute scripts as other web site visitors. The attack vector involves the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL.
Recommendations:
For Apache mod ssl module version 2.8.9 and earlier, consider updating to a version where this issue is resolved, or as a temporary workaround, enable UseCanonicalName and disable wildcard DNS to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Mod Ssl