CVE-2008-2168: XSS
Published May 13, 2008
·Updated
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
Affected Software
49 affected components
Apache HTTP Server=2.0.42
Apache HTTP Server=2.2
Apache HTTP Server=2.0.58
Apache HTTP Server=2.0.47
Apache HTTP Server=2.1
Apache HTTP Server=2.0.56
Apache HTTP Server=2.0.50
Apache HTTP Server=2.2.2
Apache HTTP Server=2.1.3
Apache HTTP Server=2.2.4
Apache HTTP Server=2.0.35
Apache HTTP Server=2.0.37
Apache HTTP Server=2.0.55
Apache HTTP Server=2.1.2
Apache HTTP Server=2.1.1
Apache HTTP Server=2.0.44
Apache HTTP Server=2.0.39
Apache HTTP Server=2.0.52
Apache HTTP Server=2.1.7
Apache HTTP Server=2.0.53
Apache HTTP Server=2.0.57
Apache HTTP Server=2.0.51
Apache HTTP Server=2.0.28-beta
Apache HTTP Server=2.0.41
Apache HTTP Server=2.0.49
Apache HTTP Server=2.1.6
Apache HTTP Server=2.0.9
Apache HTTP Server=2.0.34-beta
Apache HTTP Server=2.0.61
Apache HTTP Server=2.0.32
Apache HTTP Server=2.0.38
Apache HTTP Server=2.1.4
Apache HTTP Server=2.0.48
Apache HTTP Server=2.0.45
Apache HTTP Server=2.0.40
Apache HTTP Server=2.1.5
Apache HTTP Server=2.0.36
Apache HTTP Server=2.2.3
Apache HTTP Server=2.0.46
Apache HTTP Server=2.0.54
Apache HTTP Server=2.0.43
Apache HTTP Server=2.0.59
Apache HTTP Server=2.1.8
Apache HTTP Server=2.0.28
Apache HTTP Server=2.0
Apache HTTP Server=2.0.32-beta
Apache HTTP Server=2.2.1
Apache HTTP Server=2.0.60
Apache HTTP Server
Event History
May 13, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2168?
CVE-2008-2168 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2008-2168?
To mitigate CVE-2008-2168, you should upgrade to Apache HTTP Server version 2.2.7 or later.
3
What type of vulnerability is CVE-2008-2168?
CVE-2008-2168 is a Cross-site Scripting (XSS) vulnerability.
4
Which versions of Apache HTTP Server are affected by CVE-2008-2168?
CVE-2008-2168 affects Apache HTTP Server versions 2.2.6 and earlier.
5
Can CVE-2008-2168 affect user data?
Yes, CVE-2008-2168 can lead to unauthorized access to user data through injection of malicious scripts.