SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-0840

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page…

MEDIUM 6.8EPSS 95.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 95.1%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
95.09% probability · 100th percentile
CISA KEV
Not listed
Affected
apache/http server · oracle/application server · oracle/database server · oracle/oracle8i · oracle/oracle9i
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.