Apache 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
BID:27409
Info
Apache 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
| Bugtraq ID: | 27409 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0455 CVE-2008-0456 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2008 12:00AM |
| Updated: | May 07 2015 05:16PM |
| Credit: | Stefano Di Paola of Minded Security is credited with the discovery of this vulnerability. |
| Vulnerable: |
RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 5 Gentoo Linux CentOS CentOS 6 CentOS CentOS 5 Avaya Aura Experience Portal 6.0 Apple Mac OS X Server 10.5.7 Apple Mac OS X Server 10.5.6 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.5 Apache Software Foundation Apache 2.2.6 Apache Software Foundation Apache 2.2.5 Apache Software Foundation Apache 2.2.4 Apache Software Foundation Apache 2.2.3 Apache Software Foundation Apache 2.2.2 Apache Software Foundation Apache 2.2 Apache Software Foundation Apache 2.0.61 Apache Software Foundation Apache 2.0.60 Apache Software Foundation Apache 2.0.59 Apache Software Foundation Apache 2.0.58 Apache Software Foundation Apache 2.0.56 -dev Apache Software Foundation Apache 2.0.56 Apache Software Foundation Apache 2.0.55 Apache Software Foundation Apache 2.0.54 Apache Software Foundation Apache 2.0.53 Apache Software Foundation Apache 2.0.52 Apache Software Foundation Apache 2.0.51 Apache Software Foundation Apache 2.0.50 Apache Software Foundation Apache 2.0.49 Apache Software Foundation Apache 2.0.48 Apache Software Foundation Apache 2.0.47 Apache Software Foundation Apache 2.0.46 Apache Software Foundation Apache 2.0.45 Apache Software Foundation Apache 2.0.44 Apache Software Foundation Apache 2.0.43 Apache Software Foundation Apache 2.0.42 Apache Software Foundation Apache 2.0.41 Apache Software Foundation Apache 2.0.40 Apache Software Foundation Apache 2.0.39 Apache Software Foundation Apache 2.0.38 Apache Software Foundation Apache 2.0.37 Apache Software Foundation Apache 2.0.36 Apache Software Foundation Apache 2.0.35 Apache Software Foundation Apache 2.0.32 Apache Software Foundation Apache 2.0.28 -BETA Apache Software Foundation Apache 2.0.28 Beta Apache Software Foundation Apache 2.0.28 Apache Software Foundation Apache 2.0.9 Apache Software Foundation Apache 2.0 a9 Apache Software Foundation Apache 2.0 Apache Software Foundation Apache 1.3.39 Apache Software Foundation Apache 1.3.37 Apache Software Foundation Apache 1.3.36 Apache Software Foundation Apache 1.3.35 -dev Apache Software Foundation Apache 1.3.34 Apache Software Foundation Apache 1.3.33 Apache Software Foundation Apache 1.3.32 Apache Software Foundation Apache 1.3.31 Apache Software Foundation Apache 1.3.29 Apache Software Foundation Apache 1.3.28 Apache Software Foundation Apache 1.3.27 Apache Software Foundation Apache 1.3.26 Apache Software Foundation Apache 1.3.25 Apache Software Foundation Apache 1.3.24 Apache Software Foundation Apache 1.3.23 Apache Software Foundation Apache 1.3.22 Apache Software Foundation Apache 1.3.20 Apache Software Foundation Apache 1.3.19 Apache Software Foundation Apache 1.3.18 Apache Software Foundation Apache 1.3.17 Apache Software Foundation Apache 1.3.14 Apache Software Foundation Apache 1.3.12 Apache Software Foundation Apache 1.3.11 Apache Software Foundation Apache 1.3.3 Apache Software Foundation Apache 1.3.1 Apache Software Foundation Apache 1.3 Apache Software Foundation Apache 2.2.6-dev Apache Software Foundation Apache 2.2.5-dev Apache Software Foundation Apache 2.0.61-dev Apache Software Foundation Apache 2.0.60-dev Apache Software Foundation Apache 1.3.35 Apache Software Foundation Apache 1.3 |
| Not Vulnerable: | |
Discussion
Apache 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
Apache 'mod_negotiation' is prone to an HTML-injection and an HTTP response-splitting vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, and influence or misrepresent how web content is served, cached, or interpreted; other attacks are also possible.
Apache 'mod_negotiation' is prone to an HTML-injection and an HTTP response-splitting vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, and influence or misrepresent how web content is served, cached, or interpreted; other attacks are also possible.
Exploit / POC
Apache 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
To exploit this issue, attackers must be able to control the name of a file on the vulnerable server and to entice a victim into following a malicious URI.
The following proof-of-concept example if available:
To exploit this issue, attackers must be able to control the name of a file on the vulnerable server and to entice a victim into following a malicious URI.
The following proof-of-concept example if available:
Solution / Fix
Apache 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X Server 10.5
Apple Mac OS X Server 10.5.1
Apple Mac OS X Server 10.5.2
Apple Mac OS X Server 10.5.3
Apple Mac OS X Server 10.5.4
Apple Mac OS X Server 10.5.5
Apple Mac OS X Server 10.5.6
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X Server 10.5
-
Apple MacOSXServerUpdCombo10.5.7.dmg
http://support.apple.com/downloads/DL829/MacOSXServerUpdCombo10.5.7.dm g
Apple Mac OS X Server 10.5.1
-
Apple MacOSXServerUpdCombo10.5.7.dmg
http://support.apple.com/downloads/DL829/MacOSXServerUpdCombo10.5.7.dm g
Apple Mac OS X Server 10.5.2
-
Apple MacOSXServerUpdCombo10.5.7.dmg
http://support.apple.com/downloads/DL829/MacOSXServerUpdCombo10.5.7.dm g
Apple Mac OS X Server 10.5.3
-
Apple MacOSXServerUpdCombo10.5.7.dmg
http://support.apple.com/downloads/DL829/MacOSXServerUpdCombo10.5.7.dm g
Apple Mac OS X Server 10.5.4
-
Apple MacOSXServerUpdCombo10.5.7.dmg
http://support.apple.com/downloads/DL829/MacOSXServerUpdCombo10.5.7.dm g
Apple Mac OS X Server 10.5.5
-
Apple MacOSXServerUpdCombo10.5.7.dmg
http://support.apple.com/downloads/DL829/MacOSXServerUpdCombo10.5.7.dm g
Apple Mac OS X Server 10.5.6
-
Apple MacOSXServerUpd10.5.7.dmg
http://support.apple.com/downloads/DL828/MacOSXServerUpd10.5.7.dmg
References
Apache 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- Minded Security Labs: Advisory #MSA01150108 (Stefano di Paola)
- mod_negotiation Homepage (Apache)
- Apache mod_negotiation Xss and Http Response Splitting (Minded Security Research Labs
)