Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2008-2168

Published: 13 May 2008

Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.

Priority

Low

Status

Package Release Status
apache2
Launchpad, Ubuntu, Debian
dapper
Released (2.0.55-4ubuntu2.4)
feisty Needed
(reached end-of-life)
gutsy
Released (2.2.4-3ubuntu0.2)
hardy Not vulnerable

intrepid Not vulnerable

upstream
Released (2.2.9)
Patches:
upstream: http://svn.apache.org/viewvc?view=rev&revision=606693