LWN.net Logo

mod_perl: cross-site scripting

Package(s):mod_perl CVE #(s):CVE-2009-0796
Created:April 13, 2009 Updated:December 9, 2009
Description:

From the Mandriva advisory:

Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI (CVE-2009-0796).

Alerts:
Mandriva MDVSA-2009:091-1 2009-12-08
Mandriva MDVSA-2009:091 2009-04-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds