Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6203 (Apache)

BugsAlert Home > CVE-2007-6203 (Apache)
 
 

Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6203

Learn more about CVE-2007-6203 (Apache)
 
Tags: cve-2007-6203 apache

Related Items

      Mandriva: Updated fetchmail packages fix DoS vulnerability

      ACDSee Products Image and Archive Plug-ins Buffer Overflows

      MS08-024 - Critical: Cumulative Security Update for Internet Explorer (947864)

      CVE-2008-3514 (VirtualCenter)

      "CureIt.exe", is it good as a standalone antivirus?

      Critical Microsoft Security Alert

      FrSIRT - EMC Retrospect Denial of Service and Information Disclosure Issues

 

Pixel