CVE-2008-0005
published 2008-01-12CVE-2008-0005: mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
14.61%
96.3th percentile
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.0.35 < 2.0.63 | 2.0.63 |
| apache | http_server | >= 2.2.0 < 2.2.8 | 2.2.8 |
| apache | httpd | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.2.8-1 (bookworm) | apache2 2.2.8-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_apache4.3LOW
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m62c-mf8p-77p9: mod_proxy_ftp in Apache 2
ghsa_unreviewed·2022-05-01
CVE-2008-0005 [MEDIUM] CWE-79 GHSA-m62c-mf8p-77p9: mod_proxy_ftp in Apache 2
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
OSV
CVE-2008-0005: mod_proxy_ftp in Apache 2
osv·2008-01-12·CVSS 4.3
CVE-2008-0005 [MEDIUM] CVE-2008-0005: mod_proxy_ftp in Apache 2
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
VMware
VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability
vendor_vmware·2009-04-10·CVSS 4.6
CVE-2008-4916 [MEDIUM] VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability
VMSA-2009-0006: VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability
a. Host code execution vulnerability from a guest operating system A critical vulnerability in the virtual machine display function might allow a guest operating system to run code on the host. This issue is different from the vulnerability in a guest virtual device driver reported in VMware security advisory VMSA-2009-0005 on 2009-04-03. That vulnerability can cause a potential denial of service and is identified by CVE-2008-4916. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2009-1244 to this issue. The following table lists what action remediates the vulnerability (column 4) if a solution is available. VMware Product ============= Pr
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2008-02-04·CVSS 4.3
CVE-2006-3918 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
It was discovered that Apache did not sanitize the Expect header from
an HTTP request when it is reflected back in an error message, which
could result in browsers becoming vulnerable to cross-site scripting
attacks when processing the output. With cross-site scripting
vulnerabilities, if a user were tricked into viewing server output
during a crafted server request, a remote attacker could exploit this
to modify the contents, or steal confidential data (such as passwords),
within the same domain. This was only vulnerable in Ubuntu 6.06.
(CVE-2006-3918)
It was discovered that when configured as a proxy server and using a
threaded MPM, Apache did not properly sanitize its input. A remote
attacker could send Apache crafted date
Red Hat
mod_proxy_ftp XSS
vendor_redhat·2008-01-02·CVSS 4.3
CVE-2008-0005 [MEDIUM] CWE-79 mod_proxy_ftp XSS
mod_proxy_ftp XSS
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
Debian
CVE-2008-0005: apache2 - mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3...
vendor_debian·2008·CVSS 4.3
CVE-2008-0005 [MEDIUM] CVE-2008-0005: apache2 - mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3...
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
Scope: local
bookworm: resolved (fixed in 2.2.8-1)
bullseye: resolved (fixed in 2.2.8-1)
forky: resolved (fixed in 2.2.8-1)
sid: resolved (fixed in 2.2.8-1)
trixie: resolved (fixed in 2.2.8-1)
Apache
Apache httpd: CVE-2008-0005
vendor_apache·CVSS 4.3
CVE-2008-0005 [LOW] Apache httpd: CVE-2008-0005
Apache httpd: CVE-2008-0005
A workaround was added in the mod_proxy_ftp module. On sites where mod_proxy_ftp is enabled and a forward proxy is configured, a cross-site scripting attack is possible against Web browsers which do not correctly derive the response character set following the rules in RFC 2616. Reported to security team 2007-12-15 Issue public 2008-01-08 Update 2.0.63 released 2008-01-19 Update 2.2.8 released 2008-01-19 Affects 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0, 2.0.61, 2.0.59, 2.0.58, 2.0.55, 2.0.54, 2.0.53, 2.0.52, 2.0.51, 2.0.50, 2.0.49, 2.0.48, 2.0.47, 2.0.46, 2.0.45, 2.0.44, 2.0.43, 2.0.42, 2.0.40, 2.0.39, 2.0.37, 2.0.36, 2.0.35
Severity: low
No detection rules found.
No public exploits indexed.
http://docs.info.apple.com/article.html?artnum=307562http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.htmlhttp://lists.vmware.com/pipermail/security-announce/2009/000062.htmlhttp://marc.info/?l=bugtraq&m=124654546101607&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://marc.info/?l=bugtraq&m=130497311408250&w=2http://secunia.com/advisories/28467http://secunia.com/advisories/28471http://secunia.com/advisories/28526http://secunia.com/advisories/28607http://secunia.com/advisories/28749http://secunia.com/advisories/28977http://secunia.com/advisories/29348http://secunia.com/advisories/29420http://secunia.com/advisories/29640http://secunia.com/advisories/30732http://secunia.com/advisories/35650http://security.gentoo.org/glsa/glsa-200803-19.xmlhttp://securityreason.com/achievement_securityalert/49http://securityreason.com/securityalert/3526http://support.avaya.com/elmodocs2/security/ASA-2008-032.htmhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:014http://www.mandriva.com/security/advisories?name=MDVSA-2008:015http://www.mandriva.com/security/advisories?name=MDVSA-2008:016http://www.redhat.com/support/errata/RHSA-2008-0004.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0005.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0006.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0007.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0008.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0009.htmlhttp://www.securityfocus.com/archive/1/486167/100/0/threadedhttp://www.securityfocus.com/archive/1/505990/100/0/threadedhttp://www.securityfocus.com/bid/27234http://www.securitytracker.com/id?1019185http://www.ubuntu.com/usn/usn-575-1http://www.vupen.com/english/advisories/2008/0924/referenceshttp://www.vupen.com/english/advisories/2008/1875/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/39615https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10812https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.htmlhttp://docs.info.apple.com/article.html?artnum=307562http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.htmlhttp://lists.vmware.com/pipermail/security-announce/2009/000062.htmlhttp://marc.info/?l=bugtraq&m=124654546101607&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://marc.info/?l=bugtraq&m=130497311408250&w=2http://secunia.com/advisories/28467http://secunia.com/advisories/28471http://secunia.com/advisories/28526http://secunia.com/advisories/28607http://secunia.com/advisories/28749http://secunia.com/advisories/28977http://secunia.com/advisories/29348http://secunia.com/advisories/29420http://secunia.com/advisories/29640http://secunia.com/advisories/30732http://secunia.com/advisories/35650http://security.gentoo.org/glsa/glsa-200803-19.xmlhttp://securityreason.com/achievement_securityalert/49http://securityreason.com/securityalert/3526http://support.avaya.com/elmodocs2/security/ASA-2008-032.htmhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:014http://www.mandriva.com/security/advisories?name=MDVSA-2008:015http://www.mandriva.com/security/advisories?name=MDVSA-2008:016http://www.redhat.com/support/errata/RHSA-2008-0004.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0005.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0006.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0007.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0008.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0009.htmlhttp://www.securityfocus.com/archive/1/486167/100/0/threadedhttp://www.securityfocus.com/archive/1/505990/100/0/threadedhttp://www.securityfocus.com/bid/27234http://www.securitytracker.com/id?1019185http://www.ubuntu.com/usn/usn-575-1http://www.vupen.com/english/advisories/2008/0924/referenceshttp://www.vupen.com/english/advisories/2008/1875/references
+ 24 more references
2008-01-12
Published