PT-2012-4182 · Apache+4 · Apache Http Server+4

Published

2012-06-13

·

Updated

2024-06-15

·

CVE-2012-2687

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.x before 2.4.3
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities in the mod negotiation module. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list, when the MultiViews option is enabled. This can be exploited on sites that use mod negotiation and allow untrusted uploads to locations with MultiViews enabled.
Recommendations For Apache HTTP Server versions 2.4.x before 2.4.3, update to version 2.4.3 or later to resolve the issue. As a temporary workaround, consider disabling the MultiViews option in the mod negotiation module to minimize the risk of exploitation. Restrict access to locations where untrusted uploads are allowed, especially when MultiViews is enabled.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2013_0512
CVE-2012-2687
HPSBUX02866
OPENSUSE-SU-2024:10268-1
RHSA-2012:1591
RHSA-2012:1592
RHSA-2013:0130
RHSA-2013:0512
RHSA-2013_0130
RHSA-2013_0512

Affected Products

Apache Http Server
Centos
Hp-Ux
Red Hat
Suse