5

CVE-2012-4001

The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Mod Pagespeed Version <= 0.10.22.4
   Apache ≫ HTTP Server
Google ≫ Mod Pagespeed Version 0.10.19.1
   Apache ≫ HTTP Server
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.68% 0.475
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://developers.google.com/speed/docs/mod_pagespeed/CVE-2012-4001
Vendor Advisory
https://developers.google.com/speed/docs/mod_pagespeed/announce-0.10.22.6
Vendor Advisory