SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2003-1581

The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS…

LOW 2.6EPSS 3.08%

Does this matter?

Lower severity and a low EPSS score (3.08%). Track it; it rarely justifies an emergency change on its own.

Description

The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
EPSS
3.08% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
apache/http server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.