Vulnerability Description
Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | >= 2.0.0, < 2.0.61 |
Related Weaknesses (CWE)
References
- http://bugs.gentoo.org/show_bug.cgi?id=186219Third Party Advisory
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432Broken Link
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlMailing List
- http://marc.info/?l=bugtraq&m=124654546101607&w=2Third Party AdvisoryVDB Entry
- http://marc.info/?l=bugtraq&m=125631037611762&w=2Mailing ListThird Party Advisory
- http://secunia.com/advisories/26842Broken Link
- http://secunia.com/advisories/26952Broken Link
- http://secunia.com/advisories/27563Broken Link
- http://secunia.com/advisories/27732Broken Link
- http://secunia.com/advisories/28467Broken Link
- http://secunia.com/advisories/28471Broken Link
- http://secunia.com/advisories/28607Broken Link
- http://secunia.com/advisories/28749Broken Link
- http://secunia.com/advisories/30430Broken Link
- http://secunia.com/advisories/31651Broken Link
FAQ
What is CVE-2007-4465?
CVE-2007-4465 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitr...
How severe is CVE-2007-4465?
CVE-2007-4465 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4465?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server.