CVE-2007-6388
published 2008-01-08CVE-2007-6388: Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the…
PriorityP432medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
75.89%
99.5th percentile
Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | 1.3.2 – 1.3.39 | — |
| apache | http_server | 2.0.35 – 2.0.61 | — |
| apache | http_server | 2.2.0 – 2.2.6 | — |
| debian | apache2 | < apache2 2.2.8-1 (bookworm) | apache2 2.2.8-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →XSS vulnerability is present in Apache mod_status (server-status page); detect exploitation attempts by monitoring requests to the /server-status endpoint for injected script or HTML content ↗
- ·The vulnerability is only exploitable when the server-status page is enabled; if mod_status / server-status is disabled, the attack surface does not exist. ↗
- ·Debian marks this as 'local' scope, meaning exploitation may be constrained to local network or local access contexts depending on how server-status is exposed. ↗
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-www7-pq67-9w24: Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2
ghsa_unreviewed·2022-05-01
CVE-2007-6388 [MEDIUM] CWE-79 GHSA-www7-pq67-9w24: Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2
Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
OSV
CVE-2007-6388: Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2
osv·2008-01-08·CVSS 4.3
CVE-2007-6388 [MEDIUM] CVE-2007-6388: Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2
Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2008-02-04·CVSS 4.3
CVE-2006-3918 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
It was discovered that Apache did not sanitize the Expect header from
an HTTP request when it is reflected back in an error message, which
could result in browsers becoming vulnerable to cross-site scripting
attacks when processing the output. With cross-site scripting
vulnerabilities, if a user were tricked into viewing server output
during a crafted server request, a remote attacker could exploit this
to modify the contents, or steal confidential data (such as passwords),
within the same domain. This was only vulnerable in Ubuntu 6.06.
(CVE-2006-3918)
It was discovered that when configured as a proxy server and using a
threaded MPM, Apache did not properly sanitize its input. A remote
attacker could send Apache crafted date
Red Hat
apache mod_status cross-site scripting
vendor_redhat·2007-12-29·CVSS 4.3
CVE-2007-6388 [MEDIUM] CWE-79 apache mod_status cross-site scripting
apache mod_status cross-site scripting
Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Debian
CVE-2007-6388: apache2 - Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server...
vendor_debian·2007·CVSS 4.3
CVE-2007-6388 [MEDIUM] CVE-2007-6388: apache2 - Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server...
Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.2.8-1)
bullseye: resolved (fixed in 2.2.8-1)
forky: resolved (fixed in 2.2.8-1)
sid: resolved (fixed in 2.2.8-1)
trixie: resolved (fixed in 2.2.8-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://docs.info.apple.com/article.html?artnum=307562http://httpd.apache.org/security/vulnerabilities_13.htmlhttp://httpd.apache.org/security/vulnerabilities_20.htmlhttp://httpd.apache.org/security/vulnerabilities_22.htmlhttp://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.htmlhttp://lists.vmware.com/pipermail/security-announce/2009/000062.htmlhttp://marc.info/?l=bugtraq&m=130497311408250&w=2http://secunia.com/advisories/28467http://secunia.com/advisories/28471http://secunia.com/advisories/28526http://secunia.com/advisories/28607http://secunia.com/advisories/28749http://secunia.com/advisories/28922http://secunia.com/advisories/28965http://secunia.com/advisories/28977http://secunia.com/advisories/29420http://secunia.com/advisories/29504http://secunia.com/advisories/29640http://secunia.com/advisories/29806http://secunia.com/advisories/29988http://secunia.com/advisories/30356http://secunia.com/advisories/30430http://secunia.com/advisories/30732http://secunia.com/advisories/31142http://secunia.com/advisories/32800http://secunia.com/advisories/33200http://securityreason.com/securityalert/3541http://securitytracker.com/id?1019154http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.595748http://sunsolve.sun.com/search/document.do?assetkey=1-26-233623-1http://support.avaya.com/elmodocs2/security/ASA-2008-032.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=689039http://www-1.ibm.com/support/docview.wss?uid=swg1PK62966http://www-1.ibm.com/support/docview.wss?uid=swg1PK63273http://www-1.ibm.com/support/docview.wss?uid=swg24019245http://www-1.ibm.com/support/search.wss?rs=0&q=PK59667&apar=onlyhttp://www.fujitsu.com/global/support/software/security/products-f/interstage-200808e.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:014http://www.mandriva.com/security/advisories?name=MDVSA-2008:015http://www.mandriva.com/security/advisories?name=MDVSA-2008:016http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0004.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0005.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0006.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0007.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0008.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0009.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0261.htmlhttp://www.securityfocus.com/archive/1/488082/100/0/threadedhttp://www.securityfocus.com/archive/1/494428/100/0/threadedhttp://www.securityfocus.com/archive/1/498523/100/0/threadedhttp://www.securityfocus.com/archive/1/505990/100/0/threadedhttp://www.securityfocus.com/bid/27237http://www.ubuntu.com/usn/usn-575-1http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlhttp://www.vupen.com/english/advisories/2008/0047http://www.vupen.com/english/advisories/2008/0447/referenceshttp://www.vupen.com/english/advisories/2008/0554http://www.vupen.com/english/advisories/2008/0809/referenceshttp://www.vupen.com/english/advisories/2008/0924/referenceshttp://www.vupen.com/english/advisories/2008/0986/referenceshttp://www.vupen.com/english/advisories/2008/1224/referenceshttp://www.vupen.com/english/advisories/2008/1623/referenceshttp://www.vupen.com/english/advisories/2008/1697http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2008/05/023342-01.pdfhttps://exchange.xforce.ibmcloud.com/vulnerabilities/39472https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10272https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.htmlhttp://docs.info.apple.com/article.html?artnum=307562http://httpd.apache.org/security/vulnerabilities_13.htmlhttp://httpd.apache.org/security/vulnerabilities_20.htmlhttp://httpd.apache.org/security/vulnerabilities_22.htmlhttp://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
+ 88 more references
2008-01-08
Published