PT-2013-1606 · Apache+4 · Apache Http Server+4

Niels Heinen

·

Publicado

2013-02-18

·

Atualizado

2024-06-15

·

CVE-2012-3499

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.2.x before 2.2.24-dev Apache HTTP Server versions 2.4.x before 2.4.4
Description The issue involves multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in several modules, including mod imagemap, mod info, mod ldap, mod proxy ftp, and mod status. This is due to unescaped hostnames and URIs in HTML output. The issue was reported by Niels Heinen of Google.
Recommendations For Apache HTTP Server versions 2.2.x before 2.2.24-dev, update to version 2.2.24-dev or later. For Apache HTTP Server versions 2.4.x before 2.4.4, update to version 2.4.4 or later. As a temporary workaround, consider disabling the vulnerable modules (mod imagemap, mod info, mod ldap, mod proxy ftp, and mod status) until a patch is available.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2013_0815
CVE-2012-3499
DSA-2637-1
HPSBUX02866
OPENSUSE-SU-2024:10268-1
RHSA-2013:0815
RHSA-2013:1011
RHSA-2013:1012
RHSA-2013:1207
RHSA-2013:1208
RHSA-2013_0815
SUSE-SU-2013_0648-1
SUSE-SU-2013_0648-2

Produtos afetados

Apache Http Server
Centos
Hp-Ux
Red Hat
Suse