Apache

HTTP Server

317 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 54.71%
  • Veröffentlicht 13.05.2008 21:20:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.

Exploit
  • EPSS 51.97%
  • Veröffentlicht 25.01.2008 01:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated use...

Exploit
  • EPSS 7.64%
  • Veröffentlicht 25.01.2008 01:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject...

  • EPSS 5.54%
  • Veröffentlicht 12.01.2008 00:46:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.

  • EPSS 3.66%
  • Veröffentlicht 12.01.2008 00:46:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue

Exploit
  • EPSS 2.65%
  • Veröffentlicht 12.01.2008 00:46:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.

  • EPSS 3.31%
  • Veröffentlicht 08.01.2008 19:46:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the U...

  • EPSS 84.62%
  • Veröffentlicht 08.01.2008 18:46:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or H...

  • EPSS 5.62%
  • Veröffentlicht 08.01.2008 18:46:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb...

  • EPSS 12.91%
  • Veröffentlicht 21.12.2007 22:46:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled b...