>> Apache "mod_status" Status Pages Cross Site Scripting Vulnerability
Title : Apache "mod_status" Status Pages Cross Site Scripting Vulnerability VUPEN ID : VUPEN/ADV-2008-0047 CVE ID : CVE-2007-6388
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-01-07
Technical Description
A vulnerability has been identified in Apache, which could be exploited to conduct cross site scripting attacks. This issue is caused by an input validation error in the "mod_status" module when displaying status pages, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser.
Note: The server-status page is not enabled by default.