LWN.net Logo

apache: cross-site scripting

Package(s):apache CVE #(s):CVE-2012-3499 CVE-2012-4558
Created:February 26, 2013 Updated:April 5, 2013
Description: From the Mandriva advisory:

Various XSS (cross-site scripting vulnerability) flaws due to unescaped hostnames and URIs HTML output in mod_info, mod_status, mod_imagemap, mod_ldap, and mod_proxy_ftp (CVE-2012-3499).

XSS (cross-site scripting vulnerability) in mod_proxy_balancer manager interface (CVE-2012-4558).

Alerts:
Mandriva MDVSA-2013:015 2013-02-26
Mageia MGASA-2013-0073 2013-02-27
Slackware SSA:2013-062-01 2013-03-03
Debian DSA-2637-1 2013-03-04
Ubuntu USN-1765-1 2013-03-18
Fedora FEDORA-2013-4541 2013-04-01
Mandriva MDVSA-2013:015-1 2013-04-04
openSUSE openSUSE-SU-2013:0629-1 2013-04-05
openSUSE openSUSE-SU-2013:0632-1 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds