SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-6203

Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web…

MEDIUM 4.3EPSS 80.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 80.7%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
80.75% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
apache/http server
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.