First published: Mon Dec 03 2007(Updated: )
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Http Server | =2.0.58 | |
Apache Http Server | =2.2.0 | |
Apache Http Server | =2.0.47 | |
Apache Http Server | =2.0.50 | |
Apache Http Server | =2.2.2 | |
Apache Http Server | =2.1.3 | |
Apache Http Server | =2.2.4 | |
Apache Http Server | =2.0.55 | |
Apache Http Server | =2.1.2 | |
Apache Http Server | =2.1.1 | |
Apache Http Server | =2.0.52 | |
Apache Http Server | =2.1.7 | |
Apache Http Server | =2.0.53 | |
Apache Http Server | =2.0.57 | |
Apache Http Server | =2.0.51 | |
Apache Http Server | =2.0.49 | |
Apache Http Server | =2.1.6 | |
Apache Http Server | =2.1.4 | |
Apache Http Server | =2.0.48 | |
Apache Http Server | =2.1.5 | |
Apache Http Server | =2.2.3 | |
Apache Http Server | =2.0.46 | |
Apache Http Server | =2.0.54 | |
Apache Http Server | =2.0.59 | |
Apache Http Server | =2.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6203 is considered a medium severity vulnerability, allowing potential cross-site scripting attacks.
To fix CVE-2007-6203, upgrade the Apache HTTP Server to a patch version that addresses this vulnerability.
The affected versions include Apache HTTP Server 2.0.x and 2.2.x, specifically versions 2.0.47 through 2.2.4.
CVE-2007-6203 can facilitate cross-site scripting (XSS) attacks using the reflected HTTP Method specifier.
No, CVE-2007-6203 is not specific to any operating system; it affects the Apache HTTP Server regardless of the platform.