PT-2007-1185 · Apache+1 · Apache Http Server+1

Published

2007-06-20

·

Updated

2024-06-15

·

CVE-2006-5752

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Apache HTTP Server (httpd) (affected versions not specified)
Description: A cross-site scripting (XSS) issue exists in the mod status module when ExtendedStatus is enabled and a public server-status page is used. This allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified. The issue can lead to a cross-site scripting attack on sites where the server-status page is publicly accessible.
Recommendations: For Apache HTTP Server (httpd), disable the server-status page or restrict access to it to prevent exploitation. As a temporary workaround, consider disabling the ExtendedStatus feature in the mod status module until a patch is available. Restrict access to the mod status module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5752
HPSBUX02262
OPENSUSE-SU-2024:10623-1
RHSA-2007:0532
RHSA-2007:0533
RHSA-2007:0534
RHSA-2007:0556
RHSA-2007:0557
RHSA-2007_0534
RHSA-2007_0556
RHSA-2008:0261
RHSA-2008:0263
RHSA-2008:0523
RHSA-2008:0524
RHSA-2010:0602

Affected Products

Apache Http Server
Red Hat