CVE-2008-2939
published 2008-08-06CVE-2008-2939: Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp…
PriorityP430medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
38.95%
98.4th percentile
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | <= 2.0.63 | — |
| apache | http_server | 2.2.0 – 2.2.9 | — |
| apple | mac_os_x | <= 10.5.6 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.2.9-7 (bookworm) | apache2 2.2.9-7 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →XSS attack vector targets the mod_proxy_ftp module via a wildcard in the last directory component of an FTP URI pathname when Apache is configured for ftp-over-httpd proxying ↗
- →Vulnerable source file is proxy_ftp.c (Apache 2.0.x) and mod_proxy_ftp.c (Apache 2.2.x); monitor or audit these files for patch status ↗
- →Exploitation requires both mod_proxy and mod_proxy_ftp to be enabled on the Apache instance; detection should check for these modules being active alongside exposure to untrusted FTP URIs ↗
- ·Vulnerability is only exploitable when Apache is configured to support ftp-over-httpd proxying (mod_proxy + mod_proxy_ftp both enabled); instances without this configuration are not affected ↗
- ·Red Hat Directory Server 8 (httpd package) was marked 'Will not fix', meaning patched versions may not be available for all product lines; verify patch status per distribution ↗
- ·Debian fixed this in version 2.2.9-7 across all tracked suites (bookworm, bullseye, forky, sid, trixie) ↗
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-26m2-7wh6-pcq6: Cross-site scripting (XSS) vulnerability in proxy_ftp
ghsa_unreviewed·2022-05-01
CVE-2008-2939 [MEDIUM] CWE-79 GHSA-26m2-7wh6-pcq6: Cross-site scripting (XSS) vulnerability in proxy_ftp
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
OSV
CVE-2008-2939: Cross-site scripting (XSS) vulnerability in proxy_ftp
osv·2008-08-06·CVSS 4.3
CVE-2008-2939 [MEDIUM] CVE-2008-2939: Cross-site scripting (XSS) vulnerability in proxy_ftp
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2009-03-10·CVSS 4.3
CVE-2007-6203 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
It was discovered that Apache did not sanitize the method specifier header from
an HTTP request when it is returned in an error message, which could result in
browsers becoming vulnerable to cross-site scripting attacks when processing the
output. With cross-site scripting vulnerabilities, if a user were tricked into
viewing server output during a crafted server request, a remote attacker could
exploit this to modify the contents, or steal confidential data (such as
passwords), within the same domain. This issue only affected Ubuntu 6.06 LTS and
7.10. (CVE-2007-6203)
It was discovered that Apache was vulnerable to a cross-site request forgery
(CSRF) in the mod_proxy_balancer balancer manager. If an Apache administrator
were t
Red Hat
httpd: mod_proxy_ftp globbing XSS
vendor_redhat·2008-08-05·CVSS 4.3
CVE-2008-2939 [MEDIUM] CWE-79 httpd: mod_proxy_ftp globbing XSS
httpd: mod_proxy_ftp globbing XSS
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
A flaw was found in the mod_proxy_ftp module. Where Apache is configured to support ftp-over-httpd proxying, a remote attacker could perform a cross-site scripting attack. (CVE-2008-2939)
Package: httpd (Red Hat Directory Server 8) - Will not fix
Debian
CVE-2008-2939: apache2 - Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp mod...
vendor_debian·2008·CVSS 4.3
CVE-2008-2939 [MEDIUM] CVE-2008-2939: apache2 - Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp mod...
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
Scope: local
bookworm: resolved (fixed in 2.2.9-7)
bullseye: resolved (fixed in 2.2.9-7)
forky: resolved (fixed in 2.2.9-7)
sid: resolved (fixed in 2.2.9-7)
trixie: resolved (fixed in 2.2.9-7)
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.htmlhttp://marc.info/?l=bugtraq&m=123376588623823&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://rhn.redhat.com/errata/RHSA-2008-0967.htmlhttp://secunia.com/advisories/31384http://secunia.com/advisories/31673http://secunia.com/advisories/32685http://secunia.com/advisories/32838http://secunia.com/advisories/33156http://secunia.com/advisories/33797http://secunia.com/advisories/34219http://secunia.com/advisories/35074http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1http://support.apple.com/kb/HT3549http://svn.apache.org/viewvc?view=rev&revision=682868http://svn.apache.org/viewvc?view=rev&revision=682870http://svn.apache.org/viewvc?view=rev&revision=682871http://wiki.rpath.com/Advisories:rPSA-2008-0327http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328http://www-1.ibm.com/support/docview.wss?uid=swg1PK70197http://www-1.ibm.com/support/docview.wss?uid=swg1PK70937http://www.kb.cert.org/vuls/id/663763http://www.mandriva.com/security/advisories?name=MDVSA-2008:194http://www.mandriva.com/security/advisories?name=MDVSA-2008:195http://www.mandriva.com/security/advisories?name=MDVSA-2009:124http://www.rapid7.com/advisories/R7-0033http://www.redhat.com/support/errata/RHSA-2008-0966.htmlhttp://www.securityfocus.com/archive/1/495180/100/0/threadedhttp://www.securityfocus.com/archive/1/498566/100/0/threadedhttp://www.securityfocus.com/archive/1/498567/100/0/threadedhttp://www.securityfocus.com/bid/30560http://www.securitytracker.com/id?1020635http://www.ubuntu.com/usn/USN-731-1http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2008/2315http://www.vupen.com/english/advisories/2008/2461http://www.vupen.com/english/advisories/2009/0320http://www.vupen.com/english/advisories/2009/1297https://exchange.xforce.ibmcloud.com/vulnerabilities/44223https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11316https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7716http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.htmlhttp://marc.info/?l=bugtraq&m=123376588623823&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://rhn.redhat.com/errata/RHSA-2008-0967.htmlhttp://secunia.com/advisories/31384http://secunia.com/advisories/31673http://secunia.com/advisories/32685http://secunia.com/advisories/32838http://secunia.com/advisories/33156http://secunia.com/advisories/33797http://secunia.com/advisories/34219http://secunia.com/advisories/35074http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1http://support.apple.com/kb/HT3549http://svn.apache.org/viewvc?view=rev&revision=682868http://svn.apache.org/viewvc?view=rev&revision=682870http://svn.apache.org/viewvc?view=rev&revision=682871http://wiki.rpath.com/Advisories:rPSA-2008-0327http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328http://www-1.ibm.com/support/docview.wss?uid=swg1PK70197http://www-1.ibm.com/support/docview.wss?uid=swg1PK70937http://www.kb.cert.org/vuls/id/663763http://www.mandriva.com/security/advisories?name=MDVSA-2008:194http://www.mandriva.com/security/advisories?name=MDVSA-2008:195http://www.mandriva.com/security/advisories?name=MDVSA-2009:124http://www.rapid7.com/advisories/R7-0033http://www.redhat.com/support/errata/RHSA-2008-0966.htmlhttp://www.securityfocus.com/archive/1/495180/100/0/threadedhttp://www.securityfocus.com/archive/1/498566/100/0/threadedhttp://www.securityfocus.com/archive/1/498567/100/0/threadedhttp://www.securityfocus.com/bid/30560http://www.securitytracker.com/id?1020635http://www.ubuntu.com/usn/USN-731-1http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2008/2315http://www.vupen.com/english/advisories/2008/2461http://www.vupen.com/english/advisories/2009/0320
+ 24 more references
2008-08-06
Published