CVE Database
/

CVE-2008-0455

Back to search

CVE-2008-0455

Published: Jan 25, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.

VendorProductVersions

n/a

n/a

affected
n/a

References

GLSA-200803-19
vendor-advisory
x_refsource_GENTOO
1019256
vdb-entry
x_refsource_SECTRACK
3575
third-party-advisory
x_refsource_SREASON
RHSA-2012:1594
vendor-advisory
x_refsource_REDHAT
51607
third-party-advisory
x_refsource_SECUNIA
RHSA-2012:1592
vendor-advisory
x_refsource_REDHAT
29348
third-party-advisory
x_refsource_SECUNIA
RHSA-2013:0130
vendor-advisory
x_refsource_REDHAT
RHSA-2012:1591
vendor-advisory
x_refsource_REDHAT
27409
vdb-entry
x_refsource_BID
apache-modnegotiation-xss(39867)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2008-0455 - Security Vulnerability | QwikSec