CVE-2008-2939
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 39.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 38.95% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apache/http server · apple/mac os x · canonical/ubuntu linux · opensuse/opensuse
- Source
- secalert@redhat.com
References
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=123376588623823&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=125631037611762&w=2Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2008-0967.htmlThird Party Advisory
- http://secunia.com/advisories/31384Broken Link
- http://secunia.com/advisories/31673Broken Link
- http://secunia.com/advisories/32685Broken Link
- http://secunia.com/advisories/32838Broken Link
- http://secunia.com/advisories/33156Broken Link
- http://secunia.com/advisories/33797Broken Link
- http://secunia.com/advisories/34219Broken Link
- http://secunia.com/advisories/35074Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1Broken Link
- http://support.apple.com/kb/HT3549Third Party Advisory
- http://svn.apache.org/viewvc?view=rev&revision=682868Third Party Advisory
- http://svn.apache.org/viewvc?view=rev&revision=682870Third Party Advisory
- http://svn.apache.org/viewvc?view=rev&revision=682871Third Party Advisory
- http://wiki.rpath.com/Advisories:rPSA-2008-0327Broken Link
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328Broken Link
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK70197Third Party Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK70937Third Party Advisory
- http://www.kb.cert.org/vuls/id/663763Third Party Advisory, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:194Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:195Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:124Broken Link
- http://www.rapid7.com/advisories/R7-0033Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0966.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/495180/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/498566/100/0/threadedThird Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.