PT-2007-7093 · Apache+1 · Apache Http Server+1

Published

2007-12-03

·

Updated

2018-10-15

·

CVE-2007-6203

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.0.x through 2.2.x
Description The issue allows for potential cross-site scripting (XSS) style attacks. This occurs because the HTTP Method specifier header from an HTTP request is not sanitized when reflected back in a "413 Request Entity Too Large" error message. This could be exploited using web client components that can send arbitrary headers in requests. For example, an HTTP request containing an invalid Content-length value could be used.
Recommendations For Apache HTTP Server versions 2.0.x through 2.2.x, consider updating to a version where this issue is fixed, although the specific fixed version is not provided in the available data. As a temporary workaround, consider restricting access to components that can send arbitrary headers in requests to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6203
HPSBUX02465
HPSBUX02612

Affected Products

Apache Http Server
Hp-Ux