CVE-2002-1157: High severity mod ssl mod ssl vulnerability
Cross-site scripting vulnerability in the modssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1157?
CVE-2002-1157 has a critical severity rating due to its potential for Cross-site scripting attacks.
How do I fix CVE-2002-1157?
To fix CVE-2002-1157, you should upgrade mod_ssl to version 2.8.9 or later.
What systems are affected by CVE-2002-1157?
CVE-2002-1157 affects mod_ssl versions up to and including 2.8.9.
What kind of attack does CVE-2002-1157 enable?
CVE-2002-1157 enables remote attackers to execute scripts in the context of other web site visitors through Cross-site scripting.
How does CVE-2002-1157 exploit wildcard DNS?
CVE-2002-1157 exploits wildcard DNS when UseCanonicalName is off, allowing crafted server names to be reflected in HTTPS responses.