First published: Wed Aug 06 2008(Updated: )
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP Server | <=2.0.63 | |
Apache HTTP Server | ||
Apache HTTP Server | =2.2.0 | |
Apache HTTP Server | =2.2.1 | |
Apache HTTP Server | =2.2.2 | |
Apache HTTP Server | =2.2.3 | |
Apache HTTP Server | =2.2.4 | |
Apache HTTP Server | =2.2.6 | |
Apache HTTP Server | =2.2.8 | |
Apache HTTP Server | =2.2.9 | |
Apple Mac OS X | <=10.5.6 | |
Ubuntu Linux | =6.06 | |
Ubuntu Linux | =7.10 | |
Ubuntu Linux | =8.04 | |
openSUSE | =10.2 | |
openSUSE | =10.3 | |
openSUSE | =11.0 | |
Apache HTTP Server | >=2.2.0<=2.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.