Back

MEDIUM

httpd: Expect header XSS

Published Jul 28, 2006

Description

http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (60)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 28, 2006
Updated Aug 7, 2024
Reserved Jul 27, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date May 8, 2006