4.3

CVE-2006-5752

Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheHTTP Server Version >= 1.3.2 < 1.3.39
ApacheHTTP Server Version >= 2.0.0 < 2.0.61
ApacheHTTP Server Version >= 2.2.0 < 2.2.6
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version6.10
CanonicalUbuntu Linux Version7.04
FedoraprojectFedora Version7
RedhatEnterprise Linux Eus Version4.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 18.37% 0.951
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://bugs.gentoo.org/show_bug.cgi?id=186219
Third Party Advisory
Issue Tracking
http://www.securityfocus.com/bid/24645
Patch
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1018302
Third Party Advisory
Broken Link
VDB Entry