CVE-2008-2168
published 2008-05-13CVE-2008-2168: Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that…
PriorityP431medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
54.85%
98.9th percentile
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttp://www.example.com/Znl5g3k70ZaBUPYmN5RAGUdkskoprzGI63K4mIj2sqzbX0Kc3Fu7vfthepWhmKvjudPuJTNeK9zw5MaZ1yXJi8RJRRuPe5UahFwOblMXsIPTGh3pVjTLdim3vuTKgdazOG9 idQbIjbnpMEco8Zlo5xNRuCoviPx7x7tYYeOgc8HU46gaecJwnHY7f6GlQB8H6kBFhjoIaHE1SQPhU5VReCz1olPh5jZ%3Cfont%20size=50%3EDEFACED%3C!xc+ADw-script+AD4-alert('xss') +ADw-/script+AD4---//--↗
- →Detect UTF-7 encoded XSS payloads in URLs triggering Apache 403 Forbidden error pages; look for UTF-7 sequences such as +ADw- (+ADw- = '<') and +AD4- (+AD4- = '>') in request URIs ↗
- →Monitor HTTP requests containing URL-encoded or UTF-7 encoded script tags (e.g., +ADw-script+AD4- patterns) in the request path directed at Apache servers version 2.2.6 and earlier ↗
- →The attack vector is a crafted URL path containing UTF-7 encoded HTML/script content; the payload is reflected in the 403 error page body without charset enforcement ↗
- ·This vulnerability only affects Apache configurations where the 'AddDefaultCharset' directive has been removed; default Red Hat configurations are not affected ↗
- ·The root cause is a browser-side weakness (failure to derive response charset per RFC 2616), not solely an Apache flaw; Internet Explorer is specifically identified as the vulnerable client ↗
- ·All versions of Internet Explorer are reported affected; other browsers may also be affected under certain configurations but this has not been confirmed ↗
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2009-03-10·CVSS 4.3
CVE-2007-6203 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
It was discovered that Apache did not sanitize the method specifier header from
an HTTP request when it is returned in an error message, which could result in
browsers becoming vulnerable to cross-site scripting attacks when processing the
output. With cross-site scripting vulnerabilities, if a user were tricked into
viewing server output during a crafted server request, a remote attacker could
exploit this to modify the contents, or steal confidential data (such as
passwords), within the same domain. This issue only affected Ubuntu 6.06 LTS and
7.10. (CVE-2007-6203)
It was discovered that Apache was vulnerable to a cross-site request forgery
(CSRF) in the mod_proxy_balancer balancer manager. If an Apache administrator
were t
Red Hat
httpd: XSS via UTF-7 encoded urls on the 403 Forbidden error page
vendor_redhat·2008-05-08·CVSS 4.3
CVE-2008-2168 [MEDIUM] CWE-79 httpd: XSS via UTF-7 encoded urls on the 403 Forbidden error page
httpd: XSS via UTF-7 encoded urls on the 403 Forbidden error page
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
Statement: This is actually a flaw in browsers that do not derive the response character set as required by RFC 2616. This does not affect the default configuration of Apache httpd in Red Hat products and will only affect customers who have removed the "AddDefaultCharset" directive.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-2168
Debian
CVE-2008-2168: apache2 - Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remo...
vendor_debian·2008·CVSS 4.3
CVE-2008-2168 [MEDIUM] CVE-2008-2168: apache2 - Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remo...
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
Scope: local
bookworm: resolved (fixed in 2.2.8-1)
bullseye: resolved (fixed in 2.2.8-1)
forky: resolved (fixed in 2.2.8-1)
sid: resolved (fixed in 2.2.8-1)
trixie: resolved (fixed in 2.2.8-1)
GHSA
GHSA-wxxw-99hq-72vw: Cross-site scripting (XSS) vulnerability in Apache 2
ghsa_unreviewed·2022-05-01
CVE-2008-2168 [MEDIUM] CWE-79 GHSA-wxxw-99hq-72vw: Cross-site scripting (XSS) vulnerability in Apache 2
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
OSV
CVE-2008-2168: Cross-site scripting (XSS) vulnerability in Apache 2
osv·2008-05-13·CVSS 4.3
CVE-2008-2168 [MEDIUM] CVE-2008-2168: Cross-site scripting (XSS) vulnerability in Apache 2
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
No detection rules found.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432http://marc.info/?l=bugtraq&m=124654546101607&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://secunia.com/advisories/31651http://secunia.com/advisories/34219http://secunia.com/advisories/35650http://securityreason.com/securityalert/3889http://www.securityfocus.com/archive/1/491862/100/0/threadedhttp://www.securityfocus.com/archive/1/491901/100/0/threadedhttp://www.securityfocus.com/archive/1/491930/100/0/threadedhttp://www.securityfocus.com/archive/1/491967/100/0/threadedhttp://www.securityfocus.com/bid/29112http://www.ubuntu.com/usn/USN-731-1https://exchange.xforce.ibmcloud.com/vulnerabilities/42303https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5143http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432http://marc.info/?l=bugtraq&m=124654546101607&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://secunia.com/advisories/31651http://secunia.com/advisories/34219http://secunia.com/advisories/35650http://securityreason.com/securityalert/3889http://www.securityfocus.com/archive/1/491862/100/0/threadedhttp://www.securityfocus.com/archive/1/491901/100/0/threadedhttp://www.securityfocus.com/archive/1/491930/100/0/threadedhttp://www.securityfocus.com/archive/1/491967/100/0/threadedhttp://www.securityfocus.com/bid/29112http://www.ubuntu.com/usn/USN-731-1https://exchange.xforce.ibmcloud.com/vulnerabilities/42303https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5143
2008-05-13
Published