|
|
| |
|
| |
httpd: multiple vulnerabilities
| Package(s): | httpd |
CVE #(s): | CVE-2008-0455
CVE-2008-0456
|
| Created: | January 17, 2013 |
Updated: | February 12, 2013 |
| Description: |
From the Scientific Linux advisory:
Input sanitization flaws were found in the mod_negotiation module. A remote
attacker able to upload or create files with arbitrary names in a directory
that has the MultiViews options enabled, could use these flaws to conduct
cross-site scripting and HTTP response splitting attacks against users
visiting
the site. (CVE-2008-0455, CVE-2008-0456) |
| Alerts: |
|
( Log in to post comments)
|
|
|