CVE-2007-6421
- EPSS 3.02%
- Published 08.01.2008 19:46:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the U...
CVE-2007-6388
- EPSS 79.22%
- Published 08.01.2008 18:46:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or H...
- EPSS 5.53%
- Published 08.01.2008 18:46:00
- Last modified 09.04.2025 00:30:58
The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb...
CVE-2007-6514
- EPSS 9.68%
- Published 21.12.2007 22:46:00
- Last modified 09.04.2025 00:30:58
Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled b...
CVE-2007-5000
- EPSS 88.67%
- Published 13.12.2007 18:46:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inje...
CVE-2007-6203
- EPSS 76.25%
- Published 03.12.2007 22:46:00
- Last modified 09.04.2025 00:30:58
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using w...
CVE-2007-4465
- EPSS 4.68%
- Published 14.09.2007 00:17:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using t...
- EPSS 22.13%
- Published 23.08.2007 22:17:00
- Last modified 09.04.2025 00:30:58
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffe...
CVE-2006-5752
- EPSS 11.55%
- Published 27.06.2007 17:30:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML vi...
- EPSS 34.51%
- Published 27.06.2007 17:30:00
- Last modified 09.04.2025 00:30:58
cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with...