cbcvebase.
CVE-2012-4558
published 2013-02-26

CVE-2012-4558: Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer…

PriorityP431medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
22.91%
97.5th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server

Detection & IOCsextracted from sources · hover to see the quote

  • The XSS vulnerability exists in the balancer_handler function within the mod_proxy_balancer manager interface; monitor HTTP requests to the balancer-manager endpoint containing unsanitized/crafted strings that include script or HTML injection payloads.
  • The vulnerable component is mod_proxy_balancer; detect exploitation attempts by inspecting requests to the balancer manager interface for injected script/HTML content in query parameters or form fields.
  • ·Affected Apache HTTP Server versions span a wide range; ensure patching covers all listed versions before declaring remediation complete.
  • ·Red Hat JBoss Enterprise Web Server 1 will not receive a fix for this CVE; deployments on that platform remain permanently exposed.

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_apache4.3
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.