First published: Tue Jan 08 2008(Updated: )
Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Http Server | ||
Apache Http Server | =2.2 | |
Apache Http Server | =2.2.1 | |
Apache Http Server | =2.2.2 | |
Apache Http Server | =2.2.3 | |
Apache Http Server | =2.2.4 | |
Apache Http Server | =2.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6421 has been classified as a moderate severity vulnerability.
To fix CVE-2007-6421, you should upgrade to Apache HTTP Server version 2.2.7 or later.
CVE-2007-6421 can be exploited through cross-site scripting (XSS) attacks via specific parameters.
CVE-2007-6421 affects Apache HTTP Server versions 2.2.0 through 2.2.6.
The vulnerable parameters in CVE-2007-6421 are ss, wr, rr, and the URL.