CVE-2006-5752
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 27.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 27.78% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- apache/http server · canonical/ubuntu linux · fedoraproject/fedora · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://bugs.gentoo.org/show_bug.cgi?id=186219Issue Tracking, Third Party Advisory
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=245112Issue Tracking, Third Party Advisory
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795Third Party Advisory
- http://httpd.apache.org/security/vulnerabilities_13.htmlVendor Advisory
- http://httpd.apache.org/security/vulnerabilities_20.htmlVendor Advisory
- http://httpd.apache.org/security/vulnerabilities_22.htmlVendor Advisory
- http://lists.vmware.com/pipermail/security-announce/2009/000062.htmlMailing List, Third Party Advisory
- http://osvdb.org/37052Broken Link
- http://rhn.redhat.com/errata/RHSA-2007-0534.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2007-0556.htmlThird Party Advisory
- http://secunia.com/advisories/25827Not Applicable
- http://secunia.com/advisories/25830Not Applicable
- http://secunia.com/advisories/25873Not Applicable
- http://secunia.com/advisories/25920Not Applicable
- http://secunia.com/advisories/26273Not Applicable
- http://secunia.com/advisories/26443Not Applicable
- http://secunia.com/advisories/26458Not Applicable
- http://secunia.com/advisories/26508Not Applicable
- http://secunia.com/advisories/26822Not Applicable
- http://secunia.com/advisories/26842Not Applicable
- http://secunia.com/advisories/26993Not Applicable
- http://secunia.com/advisories/27037Not Applicable
- http://secunia.com/advisories/27563Not Applicable
- http://secunia.com/advisories/27732Not Applicable
- http://secunia.com/advisories/28212Not Applicable
- http://secunia.com/advisories/28224Not Applicable
- http://secunia.com/advisories/28606Not Applicable
- http://security.gentoo.org/glsa/glsa-200711-06.xmlThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103179-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200032-1Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.