MEDIUM · 6.8

CVE-2002-0840

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows r...

Vulnerability Description

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
ApacheHttp Server1.3
OracleApplication Server1.0.2
OracleDatabase Server8.1.7
OracleOracle8I8.1.7
OracleOracle9I9.0

References

FAQ

What is CVE-2002-0840?

CVE-2002-0840 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows r...

How severe is CVE-2002-0840?

CVE-2002-0840 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-0840?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Oracle Application Server, Oracle Database Server, Oracle Oracle8I, Oracle Oracle9I.