PT-2012-4182 · Apache+4 · Apache Http Server+4

Publicado

2012-06-13

·

Atualizado

2024-06-15

·

CVE-2012-2687

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.x before 2.4.3
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities in the mod negotiation module. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list, when the MultiViews option is enabled. This can be exploited on sites that use mod negotiation and allow untrusted uploads to locations with MultiViews enabled.
Recommendations For Apache HTTP Server versions 2.4.x before 2.4.3, update to version 2.4.3 or later to resolve the issue. As a temporary workaround, consider disabling the MultiViews option in the mod negotiation module to minimize the risk of exploitation. Restrict access to locations where untrusted uploads are allowed, especially when MultiViews is enabled.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2013_0512
CVE-2012-2687
HPSBUX02866
OPENSUSE-SU-2024:10268-1
RHSA-2012:1591
RHSA-2012:1592
RHSA-2013:0130
RHSA-2013:0512
RHSA-2013_0130
RHSA-2013_0512

Produtos afetados

Apache Http Server
Centos
Hp-Ux
Red Hat
Suse