OSVDB ID: 2107

Title: Apache HTTP Server mod_ssl Host: Header XSS

Info

Disclosure

Oct 22, 2002

Discovery

Oct 22, 2002

Dates

Exploit

Oct 22, 2002

Solution

Unknown

Description

Apache mod_ssl contains a flaw that allows a remote Cross Site Scripting attack. This flaw exists because the application does not validate server signature data upon submission to the SSI error page. This could allow a user to send a specially crafted request that would execute the embedded script within the security context of the hosting site.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
Solution: Upgrade
Exploit: Exploit Public
Disclosure: OSVDB Verified, Vendor Verified
OSVDB: Web Related

Solution

Upgrade to version 2.8.10 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Apache Software Foundation

mod_ssl

2.4.10
2.8.9

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/36218