|
|
| |
|
| |
apache: cross-site scripting
| Package(s): | apache |
CVE #(s): | CVE-2012-2687
|
| Created: | October 2, 2012 |
Updated: | April 5, 2013 |
| Description: |
From the CVE entry:
Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list. |
| Alerts: |
|
( Log in to post comments)
|
|
|