CVE-2012-3499: XSS
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-3499 to the following vulnerability:
Name: CVE-2012-3499 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3499 Assigned: 20120614 Reference: http://httpd.apache.org/security/vulnerabilities22.html Reference: http://httpd.apache.org/security/vulnerabilities24.html Reference: http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/modinfo.c?r1=1225799&r2=1413732&diffformat=h Reference: http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/modstatus.c?r1=1389564&r2=1413732&diffformat=h Reference: http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/ldap/utilldapcachemgr.c?r1=1209766&r2=1418752&diffformat=h Reference: http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/mappers/modimagemap.c?r1=1398480&r2=1413732&diffformat=h Reference: http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/modproxyftp.c?r1=1404625&r2=1413732&diffformat=h
Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) modimagemap, (2) modinfo, (3) modldap, (4) modproxyftp, and (5) modstatus modules.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3499?
CVE-2012-3499 is rated as moderate in severity due to potential security implications involving Apache HTTP Server.
How do I fix CVE-2012-3499?
To fix CVE-2012-3499, update your Apache HTTP Server to version 2.4.4 or later, or 2.2.24 or later.
What versions of Apache HTTP Server are affected by CVE-2012-3499?
CVE-2012-3499 affects Apache HTTP Server versions up to 2.4.4 and 2.2.24.
What type of vulnerability is CVE-2012-3499?
CVE-2012-3499 is a vulnerability related to improper handling of requests in the Apache HTTP Server.
Is there a workaround for CVE-2012-3499?
There is no known immediate workaround for CVE-2012-3499, making timely upgrades essential.