PT-2008-1552 · Apache+1 · Apache Http Server+1

Published

2008-01-02

·

Updated

2024-06-15

·

CVE-2007-6388

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 1.3.2 through 1.3.39 Apache HTTP Server versions 2.0.35 through 2.0.61 Apache HTTP Server versions 2.2.0 through 2.2.6
Description A cross-site scripting (XSS) issue exists in the mod status module of the Apache HTTP Server. This issue allows remote attackers to inject arbitrary web script or HTML via unspecified vectors when the server-status page is enabled. The server-status page is not enabled by default, and it is recommended to keep it non-public to avoid potential attacks.
Recommendations For Apache HTTP Server versions 1.3.2 through 1.3.39, consider disabling the mod status module to prevent exploitation. For Apache HTTP Server versions 2.0.35 through 2.0.61, restrict access to the server-status page to minimize the risk of cross-site scripting attacks. For Apache HTTP Server versions 2.2.0 through 2.2.6, avoid making the server-status page publicly accessible as a temporary workaround until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6388
HPSBUX02313
OPENSUSE-SU-2024:10623-1
RHSA-2008:0004
RHSA-2008:0005
RHSA-2008:0006
RHSA-2008:0007
RHSA-2008:0008
RHSA-2008:0009
RHSA-2008:0261
RHSA-2008:0263
RHSA-2008:0523
RHSA-2008:0524
RHSA-2008_0006
RHSA-2008_0008
RHSA-2010:0602

Affected Products

Apache Http Server
Red Hat