Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and...
Vulnerability Description
Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2002-1157
Credits & Attribution
No credits recorded in the NVD database.
References
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0374.html
- http://www.redhat.com/support/errata/RHSA-2002-243.html
- http://www.securityfocus.com/bid/6029
- http://www.redhat.com/support/errata/RHSA-2002-222.html
- http://www.redhat.com/support/errata/RHSA-2003-106.html
- http://www.redhat.com/support/errata/RHSA-2002-251.html
- http://www.debian.org/security/2002/dsa-181
- http://www.osvdb.org/2107
- http://www.linuxsecurity.com/advisories/other_advisory-2512.html
- http://www.iss.net/security_center/static/10457.php
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-072.php
- http://online.securityfocus.com/archive/1/296753
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000541
- http://www.redhat.com/support/errata/RHSA-2002-248.html
- http://www.redhat.com/support/errata/RHSA-2002-244.html
Affected Vendor
mod ssl
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.