CVE-2007-6388

Description

Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
86.869

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.2.6Windows
Update Apache to version 2.0.63Windows
Update Apache to version 1.3.39Windows
Vulnerabilities CVE-2007-6388 are fixed in Apache 1.3.41Windows
Vulnerabilities CVE-2007-6388 are fixed in Apache 2.2.8Windows
Vulnerabilities CVE-2007-6388 are fixed in Apache 2.0.63Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 4.3Windows
Update Apache to version 2.2.6 (For Linux)Linux
Update Apache to version 2.0.63 (For Linux)Linux
Update Apache to version 1.3.39 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234