{"api_version":"1","generated_at":"2026-07-24T22:37:43+00:00","cve":"CVE-2002-1157","urls":{"html":"https://cve.report/CVE-2002-1157","api":"https://cve.report/api/cve/CVE-2002-1157.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-1157","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-1157"},"summary":{"title":"CVE-2002-1157","description":"Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-11-04 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.linuxsecurity.com/advisories/other_advisory-2512.html","name":"http://www.linuxsecurity.com/advisories/other_advisory-2512.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"LinuxSecurity.com: EnGarde: mod_ssl cross-site scripting","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-251.html","name":"http://www.redhat.com/support/errata/RHSA-2002-251.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-244.html","name":"http://www.redhat.com/support/errata/RHSA-2002-244.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-222.html","name":"http://www.redhat.com/support/errata/RHSA-2002-222.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000541","name":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000541","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Home - Conectiva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/2107","name":"http://www.osvdb.org/2107","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2002-10/0374.html","name":"http://archives.neohapsis.com/archives/bugtraq/2002-10/0374.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-248.html","name":"http://www.redhat.com/support/errata/RHSA-2002-248.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2002/dsa-181","name":"http://www.debian.org/security/2002/dsa-181","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Debian -- Security Information -- DSA-181-1 libapache-mod-ssl","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-072.php","name":"http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-072.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://online.securityfocus.com/archive/1/296753","name":"http://online.securityfocus.com/archive/1/296753","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus HOME Mailing List: BugTraq","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/10457.php","name":"http://www.iss.net/security_center/static/10457.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ISS X-Force Database: apache-modssl-host-xss (10457): Apache mod_ssl HTTP Server \"Host:\" header cross-site scripting","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-243.html","name":"http://www.redhat.com/support/errata/RHSA-2002-243.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2003-106.html","name":"http://www.redhat.com/support/errata/RHSA-2003-106.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6029","name":"http://www.securityfocus.com/bid/6029","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mod_SSL Wildcard DNS Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-1157","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-1157","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"1157","vulnerable":"1","versionEndIncluding":"2.8.9","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mod_ssl","cpe5":"mod_ssl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:19:27.695Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20021026 GLSA: mod_ssl","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-10/0374.html"},{"name":"RHSA-2002:243","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-243.html"},{"name":"6029","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6029"},{"name":"RHSA-2002:222","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-222.html"},{"name":"RHSA-2003:106","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2003-106.html"},{"name":"RHSA-2002:251","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-251.html"},{"name":"DSA-181","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2002/dsa-181"},{"name":"2107","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/2107"},{"name":"ESA-20021029-027","tags":["vendor-advisory","x_refsource_ENGARDE","x_transferred"],"url":"http://www.linuxsecurity.com/advisories/other_advisory-2512.html"},{"name":"apache-modssl-host-xss(10457)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/10457.php"},{"name":"MDKSA-2002:072","tags":["vendor-advisory","x_refsource_MANDRAKE","x_transferred"],"url":"http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-072.php"},{"name":"20021023 [OpenPKG-SA-2002.010] OpenPKG Security Advisory (apache)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://online.securityfocus.com/archive/1/296753"},{"name":"CLA-2002:541","tags":["vendor-advisory","x_refsource_CONECTIVA","x_transferred"],"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000541"},{"name":"RHSA-2002:248","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-248.html"},{"name":"RHSA-2002:244","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-244.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-10-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2004-08-18T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20021026 GLSA: mod_ssl","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-10/0374.html"},{"name":"RHSA-2002:243","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-243.html"},{"name":"6029","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6029"},{"name":"RHSA-2002:222","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-222.html"},{"name":"RHSA-2003:106","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2003-106.html"},{"name":"RHSA-2002:251","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-251.html"},{"name":"DSA-181","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2002/dsa-181"},{"name":"2107","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/2107"},{"name":"ESA-20021029-027","tags":["vendor-advisory","x_refsource_ENGARDE"],"url":"http://www.linuxsecurity.com/advisories/other_advisory-2512.html"},{"name":"apache-modssl-host-xss(10457)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/10457.php"},{"name":"MDKSA-2002:072","tags":["vendor-advisory","x_refsource_MANDRAKE"],"url":"http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-072.php"},{"name":"20021023 [OpenPKG-SA-2002.010] OpenPKG Security Advisory (apache)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://online.securityfocus.com/archive/1/296753"},{"name":"CLA-2002:541","tags":["vendor-advisory","x_refsource_CONECTIVA"],"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000541"},{"name":"RHSA-2002:248","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-248.html"},{"name":"RHSA-2002:244","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-244.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-1157","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20021026 GLSA: mod_ssl","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2002-10/0374.html"},{"name":"RHSA-2002:243","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-243.html"},{"name":"6029","refsource":"BID","url":"http://www.securityfocus.com/bid/6029"},{"name":"RHSA-2002:222","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-222.html"},{"name":"RHSA-2003:106","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2003-106.html"},{"name":"RHSA-2002:251","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-251.html"},{"name":"DSA-181","refsource":"DEBIAN","url":"http://www.debian.org/security/2002/dsa-181"},{"name":"2107","refsource":"OSVDB","url":"http://www.osvdb.org/2107"},{"name":"ESA-20021029-027","refsource":"ENGARDE","url":"http://www.linuxsecurity.com/advisories/other_advisory-2512.html"},{"name":"apache-modssl-host-xss(10457)","refsource":"XF","url":"http://www.iss.net/security_center/static/10457.php"},{"name":"MDKSA-2002:072","refsource":"MANDRAKE","url":"http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-072.php"},{"name":"20021023 [OpenPKG-SA-2002.010] OpenPKG Security Advisory (apache)","refsource":"BUGTRAQ","url":"http://online.securityfocus.com/archive/1/296753"},{"name":"CLA-2002:541","refsource":"CONECTIVA","url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000541"},{"name":"RHSA-2002:248","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-248.html"},{"name":"RHSA-2002:244","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-244.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-1157","datePublished":"2004-09-01T04:00:00.000Z","dateReserved":"2002-09-26T00:00:00.000Z","dateUpdated":"2024-08-08T03:19:27.695Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-11-04 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mod_ssl:mod_ssl:*:*:*:*:*:*:*:*","versionEndIncluding":"2.8.9","matchCriteriaId":"60B71520-78FD-4935-BC0B-D1F299DD2B11"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"1157","Ordinal":"1","Title":"CVE-2002-1157","CVE":"CVE-2002-1157","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"1157","Ordinal":"1","NoteData":"Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.","Type":"Description","Title":"CVE-2002-1157"},{"CveYear":"2002","CveId":"1157","Ordinal":"2","NoteData":"2004-09-01","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"1157","Ordinal":"3","NoteData":"2004-08-17","Type":"Other","Title":"Modified"}]}}}