CVE-2008-2168
Published: 13 May 2008
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
Priority
Status
Package | Release | Status |
---|---|---|
apache2 Launchpad, Ubuntu, Debian |
dapper |
Released
(2.0.55-4ubuntu2.4)
|
feisty |
Needed
(reached end-of-life)
|
|
gutsy |
Released
(2.2.4-3ubuntu0.2)
|
|
hardy |
Not vulnerable
|
|
intrepid |
Not vulnerable
|
|
upstream |
Released
(2.2.9)
|
|
Patches: upstream: http://svn.apache.org/viewvc?view=rev&revision=606693 |