PT-2008-1553 · Apache+1 · Apache Http Server+1
Published
2008-01-09
·
Updated
2024-06-15
·
CVE-2007-6420
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.2.x
Description
A cross-site request forgery (CSRF) issue exists in the balancer-manager of mod proxy balancer, allowing remote attackers to gain privileges via unspecified vectors. The mod proxy balancer provides an administrative interface that could be vulnerable to CSRF attacks.
Recommendations
For Apache HTTP Server version 2.2.x, consider disabling the balancer-manager interface in mod proxy balancer as a temporary workaround until a patch is available. Restrict access to the administrative interface of mod proxy balancer to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server
Hp-Ux