Vulnerability Description
Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Mod Perl | 1 |
| Apache | Http Server | All versions |
Related Weaknesses (CWE)
References
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
- http://secunia.com/advisories/34597
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021508.1-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021709.1-1
- http://support.apple.com/kb/HT4435
- http://svn.apache.org/viewvc/perl/modperl/branches/1.x/lib/Apache/Status.pm?r1=1
- http://svn.apache.org/viewvc?view=rev&revision=761081PatchVendor Advisory
- http://www.gossamer-threads.com/lists/modperl/modperl-cvs/99477#99477Exploit
- http://www.gossamer-threads.com/lists/modperl/modperl/99475#99475Exploit
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:091
- http://www.securityfocus.com/archive/1/502709/100/0/threaded
- http://www.securityfocus.com/bid/34383
- http://www.securitytracker.com/id?1021988
- http://www.vupen.com/english/advisories/2009/0943
- https://bugzilla.redhat.com/show_bug.cgi?id=494402
FAQ
What is CVE-2009-0796?
CVE-2009-0796 is a vulnerability with a CVSS score of 2.6 (LOW). Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attack...
How severe is CVE-2009-0796?
CVE-2009-0796 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0796?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Mod Perl, Apache Http Server.