CVE-2006-3918
Summary
| CVE | CVE-2006-3918 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-28 00:04:00 UTC |
| Updated | 2023-11-07 01:59:00 UTC |
| Description | http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | All | All | All | All |
| Application | Apache | Http Server | 1.3 | All | All | All |
| Application | Apache | Http Server | 1.3.1 | All | All | All |
| Application | Apache | Http Server | 1.3.11 | All | win32 | All |
| Application | Apache | Http Server | 1.3.12 | All | All | All |
| Application | Apache | Http Server | 1.3.12 | All | win32 | All |
| Application | Apache | Http Server | 1.3.17 | All | All | All |
| Application | Apache | Http Server | 1.3.18 | All | All | All |
| Application | Apache | Http Server | 1.3.19 | All | All | All |
| Application | Apache | Http Server | 1.3.20 | All | All | All |
| Application | Apache | Http Server | 1.3.22 | All | All | All |
| Application | Apache | Http Server | 2.0 | All | All | All |
| Application | Apache | Http Server | 2.0.57 | All | All | All |
| Application | Apache | Http Server | 2.2 | All | All | All |
| Application | Apache | Http Server | 2.2.1 | All | All | All |
| Application | Apache | Http Server | 1.3 | All | All | All |
| Application | Apache | Http Server | 1.3.1 | All | All | All |
| Application | Apache | Http Server | 1.3.11 | All | win32 | All |
| Application | Apache | Http Server | 1.3.12 | All | All | All |
| Application | Apache | Http Server | 1.3.12 | All | win32 | All |
| Application | Apache | Http Server | 1.3.17 | All | All | All |
| Application | Apache | Http Server | 1.3.18 | All | All | All |
| Application | Apache | Http Server | 1.3.19 | All | All | All |
| Application | Apache | Http Server | 1.3.20 | All | All | All |
| Application | Apache | Http Server | 1.3.22 | All | All | All |
| Application | Apache | Http Server | 2.0 | All | All | All |
| Application | Apache | Http Server | 2.0.57 | All | All | All |
| Application | Apache | Http Server | 2.2 | All | All | All |
| Application | Apache | Http Server | 2.2.1 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 6.06 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 6.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 7.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 7.10 | All | All | All |
| Operating System | Debian | Debian Linux | 3.1 | All | All | All |
| Application | Ibm | Http Server | 6.0 | All | All | All |
| Application | Ibm | Http Server | 6.1 | All | All | All |
| Application | Ibm | Http Server | 6.0 | All | All | All |
| Application | Ibm | Http Server | 6.1 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 2.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 2.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | MLIST | lists.apache.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| ASA-2006-194 (RHSA-2006-0619) | CONFIRM | support.avaya.com | |
| SUSE update for apache and apache2 - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| '[security bulletin] HPSBUX02465 SSRT090192 rev.1 - HP-UX Running Apache-based Web Server, Remote Den' - MARC | HP | marc.info | |
| Pony Mail! | lists.apache.org | ||
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Write-up by Amit Klein: "Forging HTTP request headers with Flash" - CXSecurity.com | SREASON | securityreason.com | |
| Neohapsis Archives - Bugtraq - #0425 - Write-up by Amit Klein: "Forging HTTP request headers with Flash" | BUGTRAQ | archives.neohapsis.com | Exploit |
| Pony Mail! | MLIST | lists.apache.org | |
| rhn.redhat.com | Red Hat Support | REDHAT | rhn.redhat.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| Pony Mail! | lists.apache.org | ||
| Debian update for apache - Advisories - Secunia | SECUNIA | secunia.com | |
| Pony Mail! | lists.apache.org | ||
| rhn.redhat.com | Red Hat Support | REDHAT | rhn.redhat.com | |
| IBM HTTP Server "Expect" Header Cross-Site Scripting - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Pony Mail! | lists.apache.org | ||
| Red Hat Stronghold update for apache - Advisories - Secunia | SECUNIA | secunia.com | |
| Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness | BID | www.securityfocus.com | |
| Security Response to CVE-2006-3918: Possible Cross-Site Scripting Exploit in Apache Using Expect Headers, Seen in Flash SWF File | CONFIRM | kb.vmware.com | |
| [Apache-SVN] Revision 394965 | CONFIRM | svn.apache.org | Exploit |
| Red Hat update for apache/httpd - Advisories - Secunia | SECUNIA | secunia.com | |
| Security Advisory FSC-2010-2 | CONFIRM | www.f-secure.com | |
| Pony Mail! | lists.apache.org | ||
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityTracker.com Archives - IBM HTTP Server (IHS) Lack of Input Validation in Expect Header May Permit Cross-Site Scripting Attacks | SECTRACK | securitytracker.com | |
| '[security bulletin] HPSBOV02683 SSRT090208 rev.1 - HP Secure Web Server (SWS) for OpenVMS running Ap' - MARC | HP | marc.info | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| IBM - Subscription service - Bulletin | CONFIRM | www14.software.ibm.com | |
| USN-575-1: Apache vulnerabilities | Ubuntu | UBUNTU | www.ubuntu.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia | SECUNIA | secunia.com | |
| Pony Mail! | lists.apache.org | ||
| '[security bulletin] HPSBUX02612 SSRT100345 rev.1 - HP-UX Apache-based Web Server, Local Information' - MARC | HP | marc.info | |
| IBM notice: The page you requested cannot be displayed | AIXAPAR | www-1.ibm.com | |
| 20060801-01-P | SGI | patches.sgi.com | |
| SecurityTracker.com Archives - F-Secure Policy Manager Input Validation Bug Permits Cross-Site Scripting Attacks Via the Expect Header | SECTRACK | www.securitytracker.com | |
| Pony Mail! | lists.apache.org | ||
| F-Secure Policy Manager "Expect" Header Cross-Site Scripting - Advisories - Community | SECUNIA | secunia.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| IBM HTTP Server Two Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| Apache "Expect" Header Cross-Site Scripting Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| 20060508 Unfiltered Header Injection in Apache 1.3.34/2.0.57/2.2.1 | BUGTRAQ | archives.neohapsis.com | Exploit |
| OpenBSD update for httpd - Advisories - Secunia | SECUNIA | secunia.com | |
| Security Announcement | SUSE | www.novell.com | |
| OpenBSD 4.0 errata | OPENBSD | openbsd.org | |
| Avaya Products Apache "Expect" Header Cross-Site Scripting - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| IBM HMC Apache2 / OpenSSL Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| [security-announce] SUSE Security Announcement: Apache,Apache2 security | SUSE | lists.opensuse.org | |
| PK24631: HTTP EXPECT HEADER VALUE CAN BE ECHOED TO BROWSER UNESCAPED | AIXAPAR | www-1.ibm.com | |
| SUSE update for apache2 - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Webmail - OVH | VUPEN | www.vupen.com | |
| Pony Mail! | lists.apache.org | ||
| Ubuntu update for apache2 - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | |
| Debian -- Security Information -- DSA-1167-1 apache | DEBIAN | www.debian.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Apache | 2008-07-02 | Mark J Cox | Fixed in Apache HTTP Server 1.3.35: http://httpd.apache.org/security/vulnerabilities_13.html |
There are currently no legacy QID mappings associated with this CVE.