6.8

CVE-2002-0840

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.

Data is provided by the National Vulnerability Database (NVD)
ApacheHTTP Server Version1.3
ApacheHTTP Server Version1.3.1
ApacheHTTP Server Version1.3.3
ApacheHTTP Server Version1.3.4
ApacheHTTP Server Version1.3.6
ApacheHTTP Server Version1.3.9
ApacheHTTP Server Version1.3.11
ApacheHTTP Server Version1.3.12
ApacheHTTP Server Version1.3.14
ApacheHTTP Server Version1.3.17
ApacheHTTP Server Version1.3.18
ApacheHTTP Server Version1.3.19
ApacheHTTP Server Version1.3.20
ApacheHTTP Server Version1.3.22
ApacheHTTP Server Version1.3.23
ApacheHTTP Server Version1.3.24
ApacheHTTP Server Version1.3.25
ApacheHTTP Server Version1.3.26
ApacheHTTP Server Version2.0
ApacheHTTP Server Version2.0.28
ApacheHTTP Server Version2.0.32
ApacheHTTP Server Version2.0.35
ApacheHTTP Server Version2.0.36
ApacheHTTP Server Version2.0.37
ApacheHTTP Server Version2.0.38
ApacheHTTP Server Version2.0.39
ApacheHTTP Server Version2.0.40
ApacheHTTP Server Version2.0.41
ApacheHTTP Server Version2.0.42
OracleApplication Server Version1.0.2
OracleApplication Server Version1.0.2.1s
OracleApplication Server Version1.0.2.2
OracleApplication Server Version9.0.2
OracleApplication Server Version9.0.2 Updater2
OracleApplication Server Version9.0.2.1
OracleDatabase Server Version8.1.7
OracleDatabase Server Version9.2.1
OracleDatabase Server Version9.2.2
OracleOracle8i Version8.1.7
OracleOracle8i Version8.1.7.1
OracleOracle8i Version8.1.7_.0.0_enterprise
OracleOracle8i Version8.1.7_.1.0_enterprise
OracleOracle9i Version9.0
OracleOracle9i Version9.0.1
OracleOracle9i Version9.0.1.2
OracleOracle9i Version9.0.1.3
OracleOracle9i Version9.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 91.95% 0.997
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P