CVE-2006-5752

Description

Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform charset detection when the content-type is not specified.

Risk Information

Base Score
6.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
18.368

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.2.3Windows
Update Apache to version 2.0.61Windows
Update Apache to version 1.3.37Windows
Vulnerabilities CVE-2006-5752 are fixed in Apache 2.2.6Windows
Vulnerabilities CVE-2006-5752 are fixed in Apache 2.0.61Windows
Vulnerabilities CVE-2006-5752 are fixed in Apache 1.3.39Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 4.3Windows
Update Apache to version 2.2.3 (For Linux)Linux
Update Apache to version 2.0.61 (For Linux)Linux
Update Apache to version 1.3.37 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234