Apache Server Side Include Cross Site Scripting Vulnerability
BID:5847
Info
Apache Server Side Include Cross Site Scripting Vulnerability
| Bugtraq ID: | 5847 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0840 CVE-2002-0840 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2002 12:00AM |
| Updated: | May 09 2011 08:12PM |
| Credit: | Discovery of this vulnerability credited to "[email protected]" <[email protected]>. |
| Vulnerable: |
Sun Cobalt RaQ XTR Sun Cobalt RaQ 550 Sun Cobalt RaQ 4 Sun Cobalt Qube 3 Stonesoft StoneBeat High Availability 9.0.2 release 2 Oracle Oracle9i Standard Edition 9.2 .2 Oracle Oracle9i Standard Edition 9.2 .1 Oracle Oracle9i Standard Edition 9.2 .0.2 Oracle Oracle9i Standard Edition 9.2 .0.1 Oracle Oracle9i Standard Edition 9.0.2 Oracle Oracle9i Standard Edition 9.0.1 .3 Oracle Oracle9i Standard Edition 9.0.1 .2 Oracle Oracle9i Standard Edition 9.0.1 Oracle Oracle9i Standard Edition 9.0 Oracle Oracle9i Personal Edition 9.2.2 Oracle Oracle9i Personal Edition 9.2.1 Oracle Oracle9i Application Server Reports 9.0.2 .1 Oracle Oracle9i Application Server Reports 9.0.2 Oracle Oracle9i Application Server 9.0.2 Oracle Oracle9i Application Server 1.0.2 .2 Oracle Oracle9i Application Server 1.0.2 .1s Oracle Oracle9i Application Server 1.0.2 Oracle Oracle8i Standard Edition 8.1.7 .1 Oracle Oracle8i Standard Edition 8.1.7 Oracle Oracle8i Enterprise Edition 8.1.7 .1.0 Oracle Oracle8i Enterprise Edition 8.1.7 .0.0 Oracle Oracle8 8.1.7 IBM HTTP Server 1.3.19 HP VirtualVault 4.6 HP VirtualVault 4.5 HP OpenVMS Secure Web Server 1.2 HP OpenVMS Secure Web Server 1.1 -1 HP OpenVMS Secure Web Server 2.1-1 HP OpenView Network Node Manager 6.2 Solaris HP OpenView Network Node Manager 6.2 HP-UX 11.X HP OpenView Network Node Manager 6.2 HP-UX 10.X HP HP-UX 11.22 HP HP-UX 11.20 HP HP-UX 11.11 HP HP-UX 11.0 Apache Software Foundation Apache 2.0.42 Apache Software Foundation Apache 2.0.41 Apache Software Foundation Apache 2.0.40 Apache Software Foundation Apache 2.0.39 Apache Software Foundation Apache 2.0.38 Apache Software Foundation Apache 2.0.37 Apache Software Foundation Apache 2.0.36 Apache Software Foundation Apache 2.0.35 Apache Software Foundation Apache 2.0.32 Apache Software Foundation Apache 2.0.28 Apache Software Foundation Apache 2.0 Apache Software Foundation Apache 1.3.26 Apache Software Foundation Apache 1.3.25 Apache Software Foundation Apache 1.3.24 Apache Software Foundation Apache 1.3.23 Apache Software Foundation Apache 1.3.22 Apache Software Foundation Apache 1.3.20 Apache Software Foundation Apache 1.3.19 Apache Software Foundation Apache 1.3.18 Apache Software Foundation Apache 1.3.17 Apache Software Foundation Apache 1.3.14 Apache Software Foundation Apache 1.3.12 Apache Software Foundation Apache 1.3.11 Apache Software Foundation Apache 1.3.9 Apache Software Foundation Apache 1.3.6 Apache Software Foundation Apache 1.3.4 Apache Software Foundation Apache 1.3.3 Apache Software Foundation Apache 1.3.1 Apache Software Foundation Apache 1.3 Apache Software Foundation Apache 1.3 |
| Not Vulnerable: |
HP OpenVMS Secure Web Server 2.2 HP OpenView Network Node Manager 5.0.2 Windows NT 3.51/4.0 HP OpenView Network Node Manager 5.0 1 Solaris HP OpenView Network Node Manager 5.0 1 HP-UX HP OpenView Network Node Manager 5.0 1 Apache Software Foundation Apache 2.0.43 Apache Software Foundation Apache 1.3.27 |
Discussion
Apache Server Side Include Cross Site Scripting Vulnerability
Apache is reported to be vulnerable to cross site scripting attacks. This vulnerability is due to the SSI error pages of the webserver not being properly sanitized of malicious HTML code.
Attacker-supplied HTML and script code may be executed on a web client visiting the malicious link in the context of the webserver.
Attacks of this nature may make it possible for attackers to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.
Apache is reported to be vulnerable to cross site scripting attacks. This vulnerability is due to the SSI error pages of the webserver not being properly sanitized of malicious HTML code.
Attacker-supplied HTML and script code may be executed on a web client visiting the malicious link in the context of the webserver.
Attacks of this nature may make it possible for attackers to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.
Exploit / POC
Apache Server Side Include Cross Site Scripting Vulnerability
The following proof of concept was provided:
http://%3CIMG%20SRC%3D%22%22%20ONERROR%3D%22alert%28document%2Ecookie%29%22
%3E.apachesite.org/raise_404
The following proof of concept was provided:
http://%3CIMG%20SRC%3D%22%22%20ONERROR%3D%22alert%28document%2Ecookie%29%22
%3E.apachesite.org/raise_404
Solution / Fix
Apache Server Side Include Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Sun Cobalt RaQ 4
Sun Cobalt RaQ 550
Sun Cobalt RaQ XTR
Sun Cobalt Qube 3
Apache Software Foundation Apache 1.3.22
Apache Software Foundation Apache 1.3.23
Apache Software Foundation Apache 1.3.25
Apache Software Foundation Apache 1.3.26
HP HP-UX 11.0
HP HP-UX 11.11
HP HP-UX 11.20
HP HP-UX 11.22
Apache Software Foundation Apache 2.0
Apache Software Foundation Apache 2.0.28
Apache Software Foundation Apache 2.0.32
Apache Software Foundation Apache 2.0.35
Apache Software Foundation Apache 2.0.36
Apache Software Foundation Apache 2.0.37
Apache Software Foundation Apache 2.0.38
Apache Software Foundation Apache 2.0.39
Apache Software Foundation Apache 2.0.40
Apache Software Foundation Apache 2.0.41
Apache Software Foundation Apache 2.0.42
HP VirtualVault 4.5
HP VirtualVault 4.6
HP OpenView Network Node Manager 6.2 HP-UX 10.X
HP OpenView Network Node Manager 6.2 Solaris
HP OpenView Network Node Manager 6.2 HP-UX 11.X
Solution:
Updates are available. Please see the references for more information.
Sun Cobalt RaQ 4
-
Sun RaQ4-All-Security-2.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raq4/eng/RaQ4-All-Security-2.0. 1-16343.pkg
Sun Cobalt RaQ 550
-
Sun RaQ550-All-Security-0.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raq550/all/RaQ550-All-Security- 0.0.1-16343.pkg
Sun Cobalt RaQ XTR
-
Sun RaQ550-All-Security-0.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raq550/all/RaQ550-All-Security- 0.0.1-16343.pkg -
Sun RaQXTR-All-Security-1.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raqxtr/eng/RaQXTR-All-Security- 1.0.1-16343.pkg
Sun Cobalt Qube 3
-
Sun Qube3-All-Security-4.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/qube3/ml/Qube3-All-Security-4.0 .1-16343.pkg
Apache Software Foundation Apache 1.3.22
-
Conectiva apache-doc-1.3.26-1U8_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/apache-doc-1.3.26-1U8_4cl.i 386.rpm -
MandrakeSoft apache-common-1.3.22-10.2mdk.i586.rpm
Linux-Mandrake 7.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-devel-1.3.22-10.2mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-devel-1.3.22-10.2mdk.ia64.rpm
Mandrake Linux 8.1/ia64
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-manual-1.3.22-10.2mdk.i586.rpm
Linux-Mandrake 7.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-manual-1.3.22-10.2mdk.ia64.rpm
Mandrake Linux 8.1/ia64
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-modules-1.3.22-10.2mdk.i586.rpm
Linux-Mandrake 7.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-modules-1.3.22-10.2mdk.ia64.rpm
Mandrake Linux 8.1/ia64
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-source-1.3.22-10.2mdk.ppc.rpm
Mandrake Linux 8.0/ppc
http://www.mandrakesecure.net/en/ftp.php -
RedHat apache-1.3.27-1.6.2.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/apache-1.3.27-1.6.2.i386.rpm -
RedHat apache-1.3.27-1.6.2.sparc.rpm
ftp://updates.redhat.com/6.2/en/os/sparc/apache-1.3.27-1.6.2.sparc.rpm -
RedHat apache-1.3.27-1.7.1.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/apache-1.3.27-1.7.1.alpha.rpm -
RedHat apache-1.3.27-2.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/apache-1.3.27-2.i386.rpm -
RedHat apache-devel-1.3.27-1.6.2.alpha.rpm
ftp://updates.redhat.com/6.2/en/os/alpha/apache-devel-1.3.27-1.6.2.alp ha.rpm -
RedHat apache-devel-1.3.27-1.6.2.sparc.rpm
ftp://updates.redhat.com/6.2/en/os/sparc/apache-devel-1.3.27-1.6.2.spa rc.rpm -
RedHat apache-devel-1.3.27-1.7.1.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/apache-devel-1.3.27-1.7.1.alp ha.rpm -
RedHat apache-devel-1.3.27-2.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/apache-devel-1.3.27-2.i386.rpm -
RedHat apache-manual-1.3.27-1.7.1.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/apache-manual-1.3.27-1.7.1.al pha.rpm -
RedHat apache-manual-1.3.27-1.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/apache-manual-1.3.27-1.7.1.i38 6.rpm -
RedHat apache-manual-1.3.27-1.7.1.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/apache-manual-1.3.27-1.7.1.ia6 4.rpm -
RedHat apache-manual-1.3.27-1.7.2.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/apache-manual-1.3.27-1.7.2.ia6 4.rpm -
SCO apache-1.3.27-1.0.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-056.0/R PMS/apache-1.3.27-1.0.i386.rpm -
SCO apache-1.3.27-1.0.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-05 6.0/RPMS/apache-1.3.27-1.0.i386.rpm -
SCO apache-1.3.27-1.0.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-056.0/RPM S/apache-1.3.27-1.0.i386.rpm -
SCO apache-devel-1.3.27-1.0.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-05 6.0/RPMS/apache-devel-1.3.27-1.0.i386.rpm -
Apache Software Foundation apache_1.3.27.tar.gz
http://www.apache.org/dist/httpd/apache_1.3.27.tar.gz -
Conectiva apache-1.3.26-1U8_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/apache-1.3.26-1U8_4cl.i386. rpm -
Conectiva apache-doc-1.3.26-1U70_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/apache-doc-1.3.26-1U70_7c l.i386.rpm -
MandrakeSoft apache-1.3.22-10.2mdk.ppc.rpm
Mandrake Linux 8.0/ppc
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-common-1.3.22-10.2mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-common-1.3.22-10.2mdk.ia64.rpm
Mandrake Linux 8.1/ia64
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-common-1.3.22-10.2mdk.ppc.rpm
Mandrake Linux 8.0/ppc
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-devel-1.3.22-10.2mdk.i586.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-manual-1.3.22-10.2mdk.ppc.rpm
Mandrake Linux 8.0/ppc
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-modules-1.3.22-10.2mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-modules-1.3.22-10.2mdk.i586.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-source-1.3.22-10.2mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-source-1.3.22-10.2mdk.ia64.rpm
Mandrake Linux 8.1/ia64
http://www.mandrakesecure.net/en/ftp.php -
RedHat apache-1.3.27-1.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/apache-1.3.27-1.7.1.i386.rpm -
RedHat apache-1.3.27-1.7.1.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/apache-1.3.27-1.7.1.ia64.rpm -
RedHat apache-1.3.27-1.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/apache-1.3.27-1.7.2.i386.rpm -
RedHat apache-devel-1.3.27-1.7.2.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/apache-devel-1.3.27-1.7.2.ia64 .rpm -
RedHat apache-manual-1.3.27-1.6.2.sparc.rpm
ftp://updates.redhat.com/6.2/en/os/sparc/apache-manual-1.3.27-1.6.2.sp arc.rpm -
RedHat apache-manual-1.3.27-1.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/apache-manual-1.3.27-1.7.2.i38 6.rpm -
RedHat apache-manual-1.3.27-2.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/apache-manual-1.3.27-2.i386.rp m -
SCO apache-1.3.27-1.0.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-056. 0/RPMS/apache-1.3.27-1.0.i386.rpm -
SCO apache-devel-1.3.27-1.0.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-056.0/RPM S/apache-devel-1.3.27-1.0.i386.rpm -
SCO apache-devel-1.3.27-1.0.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-056. 0/RPMS/apache-devel-1.3.27-1.0.i386.rpm -
SCO apache-doc-1.3.27-1.0.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-05 6.0/RPMS/apache-doc-1.3.27-1.0.i386.rpm -
Conectiva apache-1.3.26-1U70_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/apache-1.3.26-1U70_7cl.i3 86.rpm -
Conectiva apache-devel-1.3.26-1U70_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/apache-devel-1.3.26-1U70_ 7cl.i386.rpm -
Conectiva apache-devel-1.3.26-1U8_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/apache-devel-1.3.26-1U8_4cl .i386.rpm -
MandrakeSoft apache-1.3.22-10.2mdk.i586.rpm
Linux-Mandrake 7.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-1.3.22-10.2mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-1.3.22-10.2mdk.i586.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-1.3.22-10.2mdk.ia64.rpm
Mandrake Linux 8.1/ia64
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-common-1.3.22-10.2mdk.i586.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-devel-1.3.22-10.2mdk.i586.rpm
Linux-Mandrake 7.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-devel-1.3.22-10.2mdk.ppc.rpm
Mandrake Linux 8.0/ppc
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-manual-1.3.22-10.2mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-manual-1.3.22-10.2mdk.i586.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-modules-1.3.22-10.2mdk.ppc.rpm
Mandrake Linux 8.0/ppc
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-source-1.3.22-10.2mdk.i586.rpm
Linux-Mandrake 7.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-source-1.3.22-10.2mdk.i586.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
OpenPKG apache-1.3.22-1.0.5.src.rpm
ftp://ftp.openpkg.org/release/1.0/UPD/apache-1.3.22-1.0.5.src.rpm -
RedHat apache-1.3.27-1.6.2.alpha.rpm
ftp://updates.redhat.com/6.2/en/os/alpha/apache-1.3.27-1.6.2.alpha.rpm -
RedHat apache-1.3.27-1.7.2.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/apache-1.3.27-1.7.2.ia64.rpm -
RedHat apache-devel-1.3.27-1.6.2.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/apache-devel-1.3.27-1.6.2.i386 .rpm -
RedHat apache-devel-1.3.27-1.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/apache-devel-1.3.27-1.7.1.i386 .rpm -
RedHat apache-devel-1.3.27-1.7.1.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/apache-devel-1.3.27-1.7.1.ia64 .rpm -
RedHat apache-devel-1.3.27-1.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/apache-devel-1.3.27-1.7.2.i386 .rpm -
RedHat apache-manual-1.3.27-1.6.2.alpha.rpm
ftp://updates.redhat.com/6.2/en/os/alpha/apache-manual-1.3.27-1.6.2.al pha.rpm -
RedHat apache-manual-1.3.27-1.6.2.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/apache-manual-1.3.27-1.6.2.i38 6.rpm -
SCO apache-devel-1.3.27-1.0.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-056.0/R PMS/apache-devel-1.3.27-1.0.i386.rpm -
SCO apache-doc-1.3.27-1.0.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-056.0/R PMS/apache-doc-1.3.27-1.0.i386.rpm -
SCO apache-doc-1.3.27-1.0.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-056.0/RPM S/apache-doc-1.3.27-1.0.i386.rpm -
SCO apache-doc-1.3.27-1.0.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-056. 0/RPMS/apache-doc-1.3.27-1.0.i386.rpm
Apache Software Foundation Apache 1.3.23
-
Apache Software Foundation apache_1.3.27.tar.gz
http://www.apache.org/dist/httpd/apache_1.3.27.tar.gz -
MandrakeSoft apache-1.3.23-4.2mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-common-1.3.23-4.2mdk.ppc.rpm
Mandrake Linux 8.2/ppc
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-devel-1.3.23-4.2mdk.ppc.rpm
Mandrake Linux 8.2/ppc
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-manual-1.3.23-4.2mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-manual-1.3.23-4.2mdk.ppc.rpm
Mandrake Linux 8.2/ppc
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-common-1.3.23-4.2mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-source-1.3.23-4.2mdk.ppc.rpm
Mandrake Linux 8.2/ppc
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-1.3.23-4.2mdk.ppc.rpm
Mandrake Linux 8.2/ppc
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-devel-1.3.23-4.2mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-modules-1.3.23-4.2mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-modules-1.3.23-4.2mdk.ppc.rpm
Mandrake Linux 8.2/ppc
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-source-1.3.23-4.2mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php
Apache Software Foundation Apache 1.3.25
-
Apache Software Foundation apache_1.3.27.tar.gz
http://www.apache.org/dist/httpd/apache_1.3.27.tar.gz
Apache Software Foundation Apache 1.3.26
-
Debian apache-dev_1.3.26-0woody3_arm.deb
http://security.debian.org/pool/updates/main/a/apache/apache-dev_1.3.2 6-0woody3_arm.deb -
Debian apache-doc_1.3.26-0woody3_all.deb
http://security.debian.org/pool/updates/main/a/apache/apache-doc_1.3.2 6-0woody3_all.deb -
Debian apache-perl_1.3.26-1-1.26-0woody2_hppa.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/a/apache-perl/apache-perl _1.3.26-1-1.26-0woody2_hppa.deb -
Debian apache-perl_1.3.26-1-1.26-0woody2_i386.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/a/apache-perl/apache-perl _1.3.26-1-1.26-0woody2_i386.deb -
Debian apache-perl_1.3.26-1-1.26-0woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/a/apache-perl/apache-perl _1.3.26-1-1.26-0woody2_m68k.deb -
Debian apache-perl_1.3.26-1-1.26-0woody2_mips.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/a/apache-perl/apache-perl _1.3.26-1-1.26-0woody2_mips.deb -
Debian apache-perl_1.3.26-1-1.26-0woody2_s390.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/a/apache-perl/apache-perl _1.3.26-1-1.26-0woody2_s390.deb -
Debian apache-ssl_1.3.26.1+1.48-0woody3_powerpc.deb
http://security.debian.org/pool/updates/main/a/apache-ssl/apache-ssl_1 .3.26.1+1.48-0woody3_powerpc.deb -
Debian apache_1.3.26-0woody3_powerpc.deb
http://security.debian.org/pool/updates/main/a/apache/apache_1.3.26-0w oody3_powerpc.deb -
MandrakeSoft apache-1.3.26-6.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Debian apache-common_1.3.26-0woody3_mipsel.deb
http://security.debian.org/pool/updates/main/a/apache/apache-common_1. 3.26-0woody3_mipsel.deb -
Debian apache-dev_1.3.26-0woody3_alpha.deb
http://security.debian.org/pool/updates/main/a/apache/apache-dev_1.3.2 6-0woody3_alpha.deb -
Debian apache-dev_1.3.26-0woody3_sparc.deb
http://security.debian.org/pool/updates/main/a/apache/apache-dev_1.3.2 6-0woody3_sparc.deb -
Debian apache-perl_1.3.26-1-1.26-0woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/a/apache-perl/apache-perl _1.3.26-1-1.26-0woody2_alpha.deb -
Debian apache-perl_1.3.26-1-1.26-0woody2_mipsel.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/a/apache-perl/apache-perl _1.3.26-1-1.26-0woody2_mipsel.deb -
Debian apache-perl_1.3.26-1-1.26-0woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/a/apache-perl/apache-perl _1.3.26-1-1.26-0woody2_powerpc.deb -
Debian apache-perl_1.3.26-1-1.26-0woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/a/apache-perl/apache-perl _1.3.26-1-1.26-0woody2_sparc.deb -
Debian apache-ssl_1.3.26.1+1.48-0woody3_arm.deb
http://security.debian.org/pool/updates/main/a/apache-ssl/apache-ssl_1 .3.26.1+1.48-0woody3_arm.deb -
Debian apache-ssl_1.3.26.1+1.48-0woody3_hppa.deb
http://security.debian.org/pool/updates/main/a/apache-ssl/apache-ssl_1 .3.26.1+1.48-0woody3_hppa.deb -
Debian apache-ssl_1.3.26.1+1.48-0woody3_i386.deb
http://security.debian.org/pool/updates/main/a/apache-ssl/apache-ssl_1 .3.26.1+1.48-0woody3_i386.deb -
Debian apache-ssl_1.3.26.1+1.48-0woody3_ia64.deb
http://security.debian.org/pool/updates/main/a/apache-ssl/apache-ssl_1 .3.26.1+1.48-0woody3_ia64.deb -
Debian apache-ssl_1.3.26.1+1.48-0woody3_m68k.deb
http://security.debian.org/pool/updates/main/a/apache-ssl/apache-ssl_1 .3.26.1+1.48-0woody3_m68k.deb -
Debian apache-ssl_1.3.26.1+1.48-0woody3_mips.deb
http://security.debian.org/pool/updates/main/a/apache-ssl/apache-ssl_1 .3.26.1+1.48-0woody3_mips.deb -
Debian apache-ssl_1.3.26.1+1.48-0woody3_mipsel.deb
http://security.debian.org/pool/updates/main/a/apache-ssl/apache-ssl_1 .3.26.1+1.48-0woody3_mipsel.deb -
Debian apache-ssl_1.3.26.1+1.48-0woody3_s390.deb
http://security.debian.org/pool/updates/main/a/apache-ssl/apache-ssl_1 .3.26.1+1.48-0woody3_s390.deb -
Debian apache_1.3.26-0woody3_alpha.deb
http://security.debian.org/pool/updates/main/a/apache/apache_1.3.26-0w oody3_alpha.deb -
Apache Software Foundation apache_1.3.27.tar.gz
http://www.apache.org/dist/httpd/apache_1.3.27.tar.gz -
Debian apache-common_1.3.26-0woody3_alpha.deb
http://security.debian.org/pool/updates/main/a/apache/apache-common_1. 3.26-0woody3_alpha.deb -
Debian apache-common_1.3.26-0woody3_arm.deb
http://security.debian.org/pool/updates/main/a/apache/apache-common_1. 3.26-0woody3_arm.deb -
Debian apache-common_1.3.26-0woody3_hppa.deb
http://security.debian.org/pool/updates/main/a/apache/apache-common_1. 3.26-0woody3_hppa.deb -
Debian apache-common_1.3.26-0woody3_i386.deb
http://security.debian.org/pool/updates/main/a/apache/apache-common_1. 3.26-0woody3_i386.deb -
Debian apache-common_1.3.26-0woody3_ia64.deb
http://security.debian.org/pool/updates/main/a/apache/apache-common_1. 3.26-0woody3_ia64.deb -
Debian apache-common_1.3.26-0woody3_m68k.deb
http://security.debian.org/pool/updates/main/a/apache/apache-common_1. 3.26-0woody3_m68k.deb -
Debian apache-common_1.3.26-0woody3_mips.deb
http://security.debian.org/pool/updates/main/a/apache/apache-common_1. 3.26-0woody3_mips.deb -
Debian apache-common_1.3.26-0woody3_powerpc.deb
http://security.debian.org/pool/updates/main/a/apache/apache-common_1. 3.26-0woody3_powerpc.deb -
Debian apache-common_1.3.26-0woody3_s390.deb
http://security.debian.org/pool/updates/main/a/apache/apache-common_1. 3.26-0woody3_s390.deb -
Debian apache-common_1.3.26-0woody3_sparc.deb
http://security.debian.org/pool/updates/main/a/apache/apache-common_1. 3.26-0woody3_sparc.deb -
Debian apache-dev_1.3.26-0woody3_hppa.deb
http://security.debian.org/pool/updates/main/a/apache/apache-dev_1.3.2 6-0woody3_hppa.deb -
Debian apache-dev_1.3.26-0woody3_i386.deb
http://security.debian.org/pool/updates/main/a/apache/apache-dev_1.3.2 6-0woody3_i386.deb -
Debian apache-dev_1.3.26-0woody3_ia64.deb
http://security.debian.org/pool/updates/main/a/apache/apache-dev_1.3.2 6-0woody3_ia64.deb -
Debian apache-dev_1.3.26-0woody3_m68k.deb
http://security.debian.org/pool/updates/main/a/apache/apache-dev_1.3.2 6-0woody3_m68k.deb -
Debian apache-dev_1.3.26-0woody3_mips.deb
http://security.debian.org/pool/updates/main/a/apache/apache-dev_1.3.2 6-0woody3_mips.deb -
MandrakeSoft apache-devel-1.3.26-6.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Debian apache_1.3.26-0woody3_sparc.deb
http://security.debian.org/pool/updates/main/a/apache/apache_1.3.26-0w oody3_sparc.deb -
MandrakeSoft apache-modules-1.3.26-6.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
OpenPKG apache-1.3.26-1.1.1.src.rpm
ftp://ftp.openpkg.org/release/1.1/UPD/apache-1.3.26-1.1.1.src.rpm -
Debian apache-dev_1.3.26-0woody3_mipsel.deb
http://security.debian.org/pool/updates/main/a/apache/apache-dev_1.3.2 6-0woody3_mipsel.deb -
Debian apache-dev_1.3.26-0woody3_powerpc.deb
http://security.debian.org/pool/updates/main/a/apache/apache-dev_1.3.2 6-0woody3_powerpc.deb -
Debian apache-dev_1.3.26-0woody3_s390.deb
http://security.debian.org/pool/updates/main/a/apache/apache-dev_1.3.2 6-0woody3_s390.deb -
Debian apache-perl_1.3.26-1-1.26-0woody2_arm.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/a/apache-perl/apache-perl _1.3.26-1-1.26-0woody2_arm.deb -
Debian apache-ssl_1.3.26.1+1.48-0woody3_alpha.deb
http://security.debian.org/pool/updates/main/a/apache-ssl/apache-ssl_1 .3.26.1+1.48-0woody3_alpha.deb -
Debian apache-ssl_1.3.26.1+1.48-0woody3_sparc.deb
http://security.debian.org/pool/updates/main/a/apache-ssl/apache-ssl_1 .3.26.1+1.48-0woody3_sparc.deb -
Debian apache_1.3.26-0woody3_arm.deb
http://security.debian.org/pool/updates/main/a/apache/apache_1.3.26-0w oody3_arm.deb -
Debian apache_1.3.26-0woody3_hppa.deb
http://security.debian.org/pool/updates/main/a/apache/apache_1.3.26-0w oody3_hppa.deb -
Debian apache_1.3.26-0woody3_i386.deb
http://security.debian.org/pool/updates/main/a/apache/apache_1.3.26-0w oody3_i386.deb -
Debian apache_1.3.26-0woody3_ia64.deb
http://security.debian.org/pool/updates/main/a/apache/apache_1.3.26-0w oody3_ia64.deb -
Debian apache_1.3.26-0woody3_m68k.deb
http://security.debian.org/pool/updates/main/a/apache/apache_1.3.26-0w oody3_m68k.deb -
Debian apache_1.3.26-0woody3_mips.deb
http://security.debian.org/pool/updates/main/a/apache/apache_1.3.26-0w oody3_mips.deb -
Debian apache_1.3.26-0woody3_mipsel.deb
http://security.debian.org/pool/updates/main/a/apache/apache_1.3.26-0w oody3_mipsel.deb -
Debian apache_1.3.26-0woody3_s390.deb
http://security.debian.org/pool/updates/main/a/apache/apache_1.3.26-0w oody3_s390.deb -
MandrakeSoft apache-common-1.3.26-6.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-manual-1.3.26-6.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft apache-source-1.3.26-6.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php
HP HP-UX 11.0
-
HP Apache 2.0.43.00
http://www.software.hp.com/ISS_products_list.html -
HP Apache 1.3.27.00
http://www.software.hp.com/ISS_products_list.html
HP HP-UX 11.11
-
HP Apache 1.3.27.00
http://www.software.hp.com/ISS_products_list.html -
HP Apache 2.0.43.00
http://www.software.hp.com/ISS_products_list.html
HP HP-UX 11.20
-
HP Apache 2.0.43.00
http://www.software.hp.com/ISS_products_list.html -
HP Apache 1.3.27.00
http://www.software.hp.com/ISS_products_list.html
HP HP-UX 11.22
-
HP Apache 1.3.27.00
http://www.software.hp.com/ISS_products_list.html -
HP Apache 2.0.43.00
http://www.software.hp.com/ISS_products_list.html
Apache Software Foundation Apache 2.0
-
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/ -
Apache Software Foundation httpd-2.0.43.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.43.tar.gz
Apache Software Foundation Apache 2.0.28
-
Apache Software Foundation httpd-2.0.43.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.43.tar.gz -
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Software Foundation Apache 2.0.32
-
Apache Software Foundation httpd-2.0.43.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.43.tar.gz -
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Software Foundation Apache 2.0.35
-
Apache Software Foundation httpd-2.0.43.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.43.tar.gz -
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Software Foundation Apache 2.0.36
-
Apache Software Foundation httpd-2.0.43.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.43.tar.gz -
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Software Foundation Apache 2.0.37
-
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/ -
Apache Software Foundation httpd-2.0.43.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.43.tar.gz
Apache Software Foundation Apache 2.0.38
-
Apache Software Foundation httpd-2.0.43.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.43.tar.gz -
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Software Foundation Apache 2.0.39
-
Apache Software Foundation httpd-2.0.43.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.43.tar.gz -
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/
Apache Software Foundation Apache 2.0.40
-
Apache Software Foundation httpd-2.0.43.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.43.tar.gz -
RedHat httpd-devel-2.0.40-11.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/httpd-devel-2.0.40-11.i386.rpm -
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/ -
RedHat httpd-2.0.40-11.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/httpd-2.0.40-11.i386.rpm -
RedHat httpd-manual-2.0.40-11.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/httpd-manual-2.0.40-11.i386.rp m
Apache Software Foundation Apache 2.0.41
-
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/ -
Apache Software Foundation httpd-2.0.43.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.43.tar.gz
Apache Software Foundation Apache 2.0.42
-
Apache Software Foundation Apache httpd 2.0.43
http://www.apache.org/dist/httpd/ -
Apache Software Foundation httpd-2.0.43.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.43.tar.gz
HP VirtualVault 4.5
-
HP PHSS_28111
s700_800 11.04 Virtualvault 4.5 IWS Update
http://itrc.hp.com/ -
HP PHSS_28098
s700_800 11.04 Virtualvault 4.5 OWS update
http://itrc.hp.com/
HP VirtualVault 4.6
-
HP PHSS_28090
s700_800 11.04 Virtualvault 4.6 IWS update
http://itrc.hp.com/ -
HP PHSS_28099
s700_800 11.04 Virtualvault 4.6 OWS update
http://itrc.hp.com/
HP OpenView Network Node Manager 6.2 HP-UX 10.X
-
HP PHSS_28704
http://ovweb.external.hp.com/cpe/patches/
HP OpenView Network Node Manager 6.2 Solaris
-
HP PSOV_03251
http://ovweb.external.hp.com/cpe/patches/
HP OpenView Network Node Manager 6.2 HP-UX 11.X
-
HP PHSS_28705
http://ovweb.external.hp.com/cpe/patches/
References
Apache Server Side Include Cross Site Scripting Vulnerability
References:
References:
- Apache 1.3.27 Released (Apache)
- Apache Homepage (Apache Software Foundation)
- Apache HTTP Server Source Code Distributions (Apache Software Foundation)
- Apache httpd Release 2.0 Changes (Apache Software Foundation)
- Oracle Security Alert #45 (Oracle)
- Oracle Security Alert #45 Revision 2 (Oracle)