CVE-2007-6421: XSS
Published Jan 8, 2008
·Updated
Cross-site scripting (XSS) vulnerability in balancer-manager in modproxybalancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
Affected Software
7 affected components
Apache HTTP Server
Apache HTTP Server=2.2
Apache HTTP Server=2.2.1
Apache HTTP Server=2.2.2
Apache HTTP Server=2.2.3
Apache HTTP Server=2.2.4
Apache HTTP Server=2.2.6
Event History
Jan 8, 2008
CVE Published
07:46 PM
Jan 9, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6421?
CVE-2007-6421 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2007-6421?
To fix CVE-2007-6421, you should upgrade to Apache HTTP Server version 2.2.7 or later.
3
What kind of attacks can exploit CVE-2007-6421?
CVE-2007-6421 can be exploited through cross-site scripting (XSS) attacks via specific parameters.
4
Which versions of Apache HTTP Server are affected by CVE-2007-6421?
CVE-2007-6421 affects Apache HTTP Server versions 2.2.0 through 2.2.6.
5
What parameters are vulnerable in CVE-2007-6421?
The vulnerable parameters in CVE-2007-6421 are ss, wr, rr, and the URL.