CVE-2012-0053

Description

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
65.535

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.0.65Windows
Multiple vulnerabilities are fixed in Apache 2.2.2Windows
Multiple vulnerabilities are fixed in Apache 2.0.65Windows
Multiple vulnerabilities are fixed in OS X Lion Update 10.7.5 (Client)Mac
Multiple vulnerabilities are fixed in OS X Lion Update 10.7.5 (Client Combo)Mac
Update Apache to version 2.0.65 (For Linux)Linux
CVE-2012-0053NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-600003OS X Lion Update 10.7.5 (Client)
PATCH-600004OS X Lion Update 10.7.5 (Client Combo)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234