CVE-2007-6388
Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 75.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 75.89% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apache/http server
- Source
- cve@mitre.org
References
- http://docs.info.apple.com/article.html?artnum=307562Third Party Advisory, VDB Entry
- http://httpd.apache.org/security/vulnerabilities_13.htmlThird Party Advisory, VDB Entry
- http://httpd.apache.org/security/vulnerabilities_20.htmlThird Party Advisory, VDB Entry
- http://httpd.apache.org/security/vulnerabilities_22.htmlThird Party Advisory, VDB Entry
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlMailing List
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.htmlThird Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2009/000062.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=130497311408250&w=2Third Party Advisory, VDB Entry
- http://secunia.com/advisories/28467Third Party Advisory, VDB Entry
- http://secunia.com/advisories/28471Third Party Advisory, VDB Entry
- http://secunia.com/advisories/28526URL Repurposed
- http://secunia.com/advisories/28607URL Repurposed
- http://secunia.com/advisories/28749URL Repurposed
- http://secunia.com/advisories/28922URL Repurposed
- http://secunia.com/advisories/28965URL Repurposed
- http://secunia.com/advisories/28977URL Repurposed
- http://secunia.com/advisories/29420URL Repurposed
- http://secunia.com/advisories/29504URL Repurposed
- http://secunia.com/advisories/29640URL Repurposed
- http://secunia.com/advisories/29806URL Repurposed
- http://secunia.com/advisories/29988URL Repurposed
- http://secunia.com/advisories/30356URL Repurposed
- http://secunia.com/advisories/30430URL Repurposed
- http://secunia.com/advisories/30732URL Repurposed
- http://secunia.com/advisories/31142URL Repurposed
- http://secunia.com/advisories/32800URL Repurposed
- http://secunia.com/advisories/33200URL Repurposed
- http://securityreason.com/securityalert/3541URL Repurposed
- http://securitytracker.com/id?1019154Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.