CVE-2008-2939
Published: 6 August 2008
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
Priority
Status
Package | Release | Status |
---|---|---|
apache Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
|
feisty |
Not vulnerable
|
|
gutsy |
Does not exist
|
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
upstream |
Not vulnerable
|
|
apache2 Launchpad, Ubuntu, Debian |
dapper |
Released
(2.0.55-4ubuntu2.4)
|
feisty |
Needed
(reached end-of-life)
|
|
gutsy |
Released
(2.2.4-3ubuntu0.2)
|
|
hardy |
Released
(2.2.8-1ubuntu0.4)
|
|
intrepid |
Not vulnerable
(2.2.9-7ubuntu1)
|
|
upstream |
Released
(2.2.9-7)
|
|
Patches: other: http://svn.apache.org/viewvc?view=rev&revision=682870 |