PT-2013-1606 · Apache+4 · Apache Http Server+4

Niels Heinen

·

Published

2013-02-18

·

Updated

2024-06-15

·

CVE-2012-3499

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.2.x before 2.2.24-dev Apache HTTP Server versions 2.4.x before 2.4.4
Description The issue involves multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in several modules, including mod imagemap, mod info, mod ldap, mod proxy ftp, and mod status. This is due to unescaped hostnames and URIs in HTML output. The issue was reported by Niels Heinen of Google.
Recommendations For Apache HTTP Server versions 2.2.x before 2.2.24-dev, update to version 2.2.24-dev or later. For Apache HTTP Server versions 2.4.x before 2.4.4, update to version 2.4.4 or later. As a temporary workaround, consider disabling the vulnerable modules (mod imagemap, mod info, mod ldap, mod proxy ftp, and mod status) until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2013_0815
CVE-2012-3499
DSA-2637-1
HPSBUX02866
OPENSUSE-SU-2024:10268-1
RHSA-2013:0815
RHSA-2013:1011
RHSA-2013:1012
RHSA-2013:1207
RHSA-2013:1208
RHSA-2013_0815
SUSE-SU-2013_0648-1
SUSE-SU-2013_0648-2

Affected Products

Apache Http Server
Centos
Hp-Ux
Red Hat
Suse