Title : Apache HTTPd "Expect" Header Handling Client-Side Cross Site Scripting Vulnerability VUPEN ID : VUPEN/ADV-2006-2963 CVE ID : CVE-2006-3918
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-07-25
Technical Description
A vulnerability has been identified in Apache, which could be exploited by attackers to execute arbitrary scripting code. This flaw is due to an input validation error in the "modules/http/http_protocol.c" script when processing malformed "Expect:" headers, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site via a specially crafted Flash file.