CVE Database
/

CVE-2006-3918

Back to search

CVE-2006-3918

Published: Jul 28, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2010-1572
vdb-entry
x_refsource_VUPEN
28749
third-party-advisory
x_refsource_SECUNIA
DSA-1167
vendor-advisory
x_refsource_DEBIAN
19661
vdb-entry
x_refsource_BID
21744
third-party-advisory
x_refsource_SECUNIA
HPSBUX02465
vendor-advisory
x_refsource_HP
1024144
vdb-entry
x_refsource_SECTRACK
22317
third-party-advisory
x_refsource_SECUNIA
22523
third-party-advisory
x_refsource_SECUNIA
SSRT090208
vendor-advisory
x_refsource_HP
ADV-2006-5089
vdb-entry
x_refsource_VUPEN
ADV-2006-3264
vdb-entry
x_refsource_VUPEN
21598
third-party-advisory
x_refsource_SECUNIA
21399
third-party-advisory
x_refsource_SECUNIA
SSRT090192
vendor-advisory
x_refsource_HP
oval:org.mitre.oval:def:10352
vdb-entry
signature
x_refsource_OVAL
21478
third-party-advisory
x_refsource_SECUNIA
RHSA-2006:0619
vendor-advisory
x_refsource_REDHAT
21986
third-party-advisory
x_refsource_SECUNIA
HPSBUX02612
vendor-advisory
x_refsource_HP
ADV-2006-4207
vdb-entry
x_refsource_VUPEN
HPSBOV02683
vendor-advisory
x_refsource_HP
21848
third-party-advisory
x_refsource_SECUNIA
RHSA-2006:0618
vendor-advisory
x_refsource_REDHAT
PK24631
vendor-advisory
x_refsource_AIXAPAR
SUSE-SA:2008:021
vendor-advisory
x_refsource_SUSE
RHSA-2006:0692
vendor-advisory
x_refsource_REDHAT
40256
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2006:051
vendor-advisory
x_refsource_SUSE
ADV-2006-2963
vdb-entry
x_refsource_VUPEN
21174
third-party-advisory
x_refsource_SECUNIA
SSRT100345
vendor-advisory
x_refsource_HP
USN-575-1
vendor-advisory
x_refsource_UBUNTU
oval:org.mitre.oval:def:12238
vdb-entry
signature
x_refsource_OVAL
29640
third-party-advisory
x_refsource_SECUNIA
1294
third-party-advisory
x_refsource_SREASON
[3.9] 012: SECURITY FIX: October 7, 2006
vendor-advisory
x_refsource_OPENBSD
PK27875
vendor-advisory
x_refsource_AIXAPAR
21172
third-party-advisory
x_refsource_SECUNIA
1016569
vdb-entry
x_refsource_SECTRACK
ADV-2006-2964
vdb-entry
x_refsource_VUPEN
22140
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now