Back

LOW

httpd: Injection of arbitrary text into log files when DNS resolution is enabled

Published Feb 5, 2010

Description

The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 5, 2010
Updated Sep 16, 2024
Reserved Feb 5, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Mar 4, 2003