PoC Index

CVE-2002-0840

MEDIUM 6.8EPSS 95.1%

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.

CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
95.09% chance of exploitation in the next 30 days, 100th percentile
Published
2004-09-01
Updated
2024-08-08

ExploitDB entries (1)

References

Related