LWN.net Logo

apache-conf: cross-site scripting

Package(s):apache-conf CVE #(s):CVE-2009-2823
Created:November 16, 2009 Updated:January 7, 2010
Description:

From the Mandriva advisory:

The Apache HTTP Server enables the HTTP TRACE method per default which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software (CVE-2009-2823).

Alerts:
Mandriva MDVSA-2009:300-1 2010-01-07
Mandriva MDVSA-2009:300-2 2010-01-07
Mandriva MDVSA-2009:300 2009-11-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds