cbcvebase.
CVE-2008-2939
published 2008-08-06

CVE-2008-2939: Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp…

PriorityP430medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
38.95%
98.4th percentile
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.

Affected

10 ranges
VendorProductVersion rangeFixed in
apachehttp_server<= 2.0.63
apachehttp_server2.2.0 – 2.2.9
applemac_os_x<= 10.5.6
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianapache2< apache2 2.2.9-7 (bookworm)apache2 2.2.9-7 (bookworm)
opensuseopensuse
opensuseopensuse
opensuseopensuse

Detection & IOCsextracted from sources · hover to see the quote

  • XSS attack vector targets the mod_proxy_ftp module via a wildcard in the last directory component of an FTP URI pathname when Apache is configured for ftp-over-httpd proxying
  • Vulnerable source file is proxy_ftp.c (Apache 2.0.x) and mod_proxy_ftp.c (Apache 2.2.x); monitor or audit these files for patch status
  • Exploitation requires both mod_proxy and mod_proxy_ftp to be enabled on the Apache instance; detection should check for these modules being active alongside exposure to untrusted FTP URIs
  • ·Vulnerability is only exploitable when Apache is configured to support ftp-over-httpd proxying (mod_proxy + mod_proxy_ftp both enabled); instances without this configuration are not affected
  • ·Red Hat Directory Server 8 (httpd package) was marked 'Will not fix', meaning patched versions may not be available for all product lines; verify patch status per distribution
  • ·Debian fixed this in version 2.2.9-7 across all tracked suites (bookworm, bullseye, forky, sid, trixie)

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.