CVE-2002-0840
published 2002-10-11CVE-2002-0840: Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
94.01%
99.8th percentile
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttp://%3CIMG%20SRC%3D%22%22%20ONERROR%3D%22alert%28document%2Ecookie%29%22%0A%3E.apachesite.org/raise_404↗
- →XSS payload is injected via the HTTP Host: header, which is reflected unsanitized in Apache's default SSI error page. Monitor/alert on Host header values containing HTML/script tags or URL-encoded equivalents (e.g., %3C, %3E, ONERROR=, <script>). ↗
- →The attack vector requires a crafted Host header containing an injected IMG or script tag (e.g., <IMG SRC="" ONERROR="alert(document.cookie)">) sent to trigger a 404 error page on the vulnerable Apache server. ↗
- →The vulnerability is only exploitable when Apache's UseCanonicalName directive is set to 'Off' and wildcard DNS is present. Check server configuration for this combination. ↗
- →Attacks may result in theft of cookie-based authentication credentials. Monitor for unexpected cookie exfiltration or document.cookie references in error page responses. ↗
- ·Vulnerability only triggers when UseCanonicalName is 'Off'; servers with UseCanonicalName 'On' are not affected. ↗
- ·Affected versions are Apache 2.0 before 2.0.43 and Apache 1.3.x up to 1.3.26. Fixed in Apache 2.0.43. ↗
- ·This is a distinct vulnerability from CAN-2002-1157, though both relate to XSS in Apache error pages. ↗
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat7.5HIGH
vendor_debian6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rg25-cp4q-r4c8: Cross-site scripting (XSS) vulnerability in the default error page of Apache 2
ghsa_unreviewed·2022-05-03
CVE-2002-0840 [MEDIUM] GHSA-rg25-cp4q-r4c8: Cross-site scripting (XSS) vulnerability in the default error page of Apache 2
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
OSV
CVE-2002-0840: Cross-site scripting (XSS) vulnerability in the default error page of Apache 2
osv·2002-10-11·CVSS 6.8
CVE-2002-0840 [MEDIUM] CVE-2002-0840: Cross-site scripting (XSS) vulnerability in the default error page of Apache 2
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
Red Hat
security flaw
vendor_redhat·2002-10-22·CVSS 7.5
CVE-2002-1157 [HIGH] security flaw
security flaw
Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.
Red Hat
security flaw
vendor_redhat·2002-10-02·CVSS 6.8
CVE-2002-0840 [MEDIUM] security flaw
security flaw
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
Debian
CVE-2002-0840: apache2 - Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0...
vendor_debian·2002·CVSS 6.8
CVE-2002-0840 [MEDIUM] CVE-2002-0840: apache2 - Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0...
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
Scope: local
bookworm: resolved (fixed in 2.0.43-1)
bullseye: resolved (fixed in 2.0.43-1)
forky: resolved (fixed in 2.0.43-1)
sid: resolved (fixed in 2.0.43-1)
trixie: resolved (fixed in 2.0.43-1)
No detection rules found.
Bugzilla
CVE-2002-0840 security flaw
bugzilla·2018-08-16·CVSS 6.8
CVE-2002-0840 [MEDIUM] CVE-2002-0840 security flaw
CVE-2002-0840 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
Bugzilla
CVE-2002-1157 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2002-1157 [HIGH] CVE-2002-1157 security flaw
CVE-2002-1157 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.
Bugzilla
XSS vulnerabilities
bugzilla·2002-10-02
[MEDIUM] XSS vulnerabilities
XSS vulnerabilities
Apache 2.0.43 should be released shortly to address this....
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0840
Discussion:
Fixed in RHSA-2002:222
ftp://patches.sgi.com/support/free/security/advisories/20021105-02-Ihttp://archives.neohapsis.com/archives/bugtraq/2002-10/0254.htmlhttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0003.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000530http://marc.info/?l=apache-httpd-announce&m=103367938230488&w=2http://marc.info/?l=bugtraq&m=103357160425708&w=2http://marc.info/?l=bugtraq&m=103376585508776&w=2http://online.securityfocus.com/advisories/4617http://www.apacheweek.com/issues/02-10-04http://www.debian.org/security/2002/dsa-187http://www.debian.org/security/2002/dsa-188http://www.debian.org/security/2002/dsa-195http://www.kb.cert.org/vuls/id/240329http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-068.phphttp://www.linuxsecurity.com/advisories/other_advisory-2414.htmlhttp://www.osvdb.org/862http://www.redhat.com/support/errata/RHSA-2002-222.htmlhttp://www.redhat.com/support/errata/RHSA-2002-243.htmlhttp://www.redhat.com/support/errata/RHSA-2002-244.htmlhttp://www.redhat.com/support/errata/RHSA-2002-248.htmlhttp://www.redhat.com/support/errata/RHSA-2002-251.htmlhttp://www.redhat.com/support/errata/RHSA-2003-106.htmlhttp://www.securityfocus.com/bid/5847https://exchange.xforce.ibmcloud.com/vulnerabilities/10241https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd00b45b93fda4a5bd013b28587207d0e00f99f6e3308dbb6025f3b01%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Eftp://patches.sgi.com/support/free/security/advisories/20021105-02-Ihttp://archives.neohapsis.com/archives/bugtraq/2002-10/0254.htmlhttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0003.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000530http://marc.info/?l=apache-httpd-announce&m=103367938230488&w=2http://marc.info/?l=bugtraq&m=103357160425708&w=2http://marc.info/?l=bugtraq&m=103376585508776&w=2http://online.securityfocus.com/advisories/4617http://www.apacheweek.com/issues/02-10-04http://www.debian.org/security/2002/dsa-187http://www.debian.org/security/2002/dsa-188http://www.debian.org/security/2002/dsa-195http://www.kb.cert.org/vuls/id/240329http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-068.phphttp://www.linuxsecurity.com/advisories/other_advisory-2414.htmlhttp://www.osvdb.org/862http://www.redhat.com/support/errata/RHSA-2002-222.htmlhttp://www.redhat.com/support/errata/RHSA-2002-243.htmlhttp://www.redhat.com/support/errata/RHSA-2002-244.htmlhttp://www.redhat.com/support/errata/RHSA-2002-248.htmlhttp://www.redhat.com/support/errata/RHSA-2002-251.htmlhttp://www.redhat.com/support/errata/RHSA-2003-106.htmlhttp://www.securityfocus.com/bid/5847https://exchange.xforce.ibmcloud.com/vulnerabilities/10241https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd00b45b93fda4a5bd013b28587207d0e00f99f6e3308dbb6025f3b01%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
2002-10-11
Published